Tashkent, Uzbekistan (UzDaily.uz) — Customers of 12 Uzbek banks have become among the targets of a new version of the RedWing Stealer Android malware, which allows attackers to intercept SMS messages, read notifications and obtain other data from infected devices.
F6 identified more than 800 samples of the malware distributed between May and September 2026. F6 reported this.
RedWing Stealer is a new version of the RedWing malware family. Unlike an earlier version of the banking trojan, which was primarily focused on remotely controlling compromised devices, the new modification is designed mainly to collect information.
According to specialists from F6’s Threat Intelligence department, the malware was distributed disguised as various Android applications. These included services for viewing 18+ photos and videos, VPN applications, as well as modifications and cheats for popular mobile games.
In particular, RedWing Stealer was disguised as applications associated with Minecraft, Roblox, Standoff 2, Brawl Stars, Oxide, Exile, Skyrim and PUBG. Fake VPN applications were distributed under the names Gosu VPN, KingVPN, KrakenVPN, HideMeVPN and FullVPN. The malware was also disguised as GooglePhoto.apk and YandexPhoto.apk.
Such applications may imitate their advertised functions while simultaneously carrying out malicious operations in the background.
F6’s research showed that RedWing Stealer targets users in several countries. The list of targets includes customers of 16 Russian, 12 Uzbek and seven Kazakh banks. The malware also targets customers of nine Russian marketplaces and eight microfinance organizations.
After installation, RedWing Stealer searches the device for SMS messages from specific senders and sends the information to the malware operators. This creates a potential threat to users of banking services where SMS messages are used to confirm transactions or receive one-time codes.
In addition to SMS messages, the malware can read push notifications and obtain information about the device, its location and status, connected SIM cards, call history, contacts and installed applications.
RedWing Stealer can also send SMS messages and USSD requests on its own, open web links and hide its icon on the device.
To operate, the malicious application requires the user to grant it a number of permissions. First, the program requests full access to SMS messages, allowing it to read and send messages, including USSD commands.
The application then requests permission to run in the background and start automatically, allowing it to continue operating after the user exits the application or restarts the device.
After obtaining the necessary permissions, the program asks the user to enter a PIN code. According to F6’s research, the entered data is immediately sent to the attackers’ server. The application then switches to background mode and continues to transmit information from the device without the user’s knowledge.
“RedWing shows how the growth of malware offerings on the underground market is leading to an increase in the scale of cybercrime attacks,” said Elena Shamshina, head of F6’s Threat Intelligence department.
According to her, the several hundred RedWing Stealer samples identified by specialists demonstrate the malware’s ability to be adapted for various criminal schemes.
F6 recommends that users install Android applications only from trusted sources and avoid downloading APK files through links received via messengers, forums, advertisements and unverified websites. Users are also advised to disable the installation of applications from unknown sources and carefully check the permissions requested by applications.
Special attention should be paid to access to SMS messages, notifications and the Accessibility service. According to F6, such permissions can give malicious applications additional capabilities to control a device.
Users should also avoid entering PIN codes, passwords, banking details and verification codes into unexpected forms appearing on the screen. If an infection is suspected, F6 recommends deleting the malicious application, checking the permissions granted to it and scanning the device with antivirus software.
If an application has been given access to SMS messages, notifications or Accessibility services, users should use another device to change passwords for important accounts and check their banking transactions.
If a bank card has been compromised, specialists recommend blocking it through the bank immediately.
For information security teams, F6 recommends taking users’ geolocation data into account, checking applications that receive SMS messages containing one-time codes, and implementing additional mechanisms to detect third-party malicious applications and software with access to the Accessibility service.
According to F6, banks can counter such attacks with anti-fraud solutions that analyze session and behavioral data, as well as technologies for detecting suspicious activity that take into account information about both the sender and recipient of a payment.