Skip to content

Malware

RedAlert2

RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps.

RedAlert2 is a Android malware family.

Background

RedAlert 2 is a more recent Android threat that lets attackers harvest the login credentials of a range of mobile banking applications. It operates by drawing a counterfeit login screen on top of the legitimate one and forwarding any entered credentials to a C2 server. It can also intercept and suppress incoming calls from banks so that victims are not alerted. For distribution, RedAlert 2 relies on third-party app marketplaces, masquerading as genuine apps such as Viber and Whatsapp or posing as bogus Adobe Flash Player updates.


Source: Malpedia (Fraunhofer FKIE).