RedHook Android malware can quietly hijack your phone
A new Android malware strain called RedHook has been identified, capable of silently hijacking infected devices. The malware is distributed through social engineering attacks, where victims receive a phone call from an impersonator claiming to be from a bank or government agency, followed by a link to a fake Google Play page. Once installed, RedHook can steal credentials, intercept two-factor authentication codes, and exfiltrate sensitive data. The malware targets users globally, with initial reports indicating activity in Europe and Asia. Security researchers warn that RedHook uses advanced obfuscation techniques to evade detection by standard antivirus software. No official statement from Google has been released yet, but users are advised to only install apps from the official Play Store and avoid clicking on unsolicited links.
Global Impact
RedHook represents a significant escalation in mobile malware sophistication, targeting the trust layer of phone calls and SMS. Economically, it could drive higher spending on mobile security software and insurance for financial institutions.