Breaking
Live threat feed August 18, 2026 | 15:20 UTC
6569 CVEs This Month
10 Actively Exploited
0 Ransomware Activity
34 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Cybersecurity News

RedHook Android Malware Exploits Wireless ADB for Shell Access

RedHook Android Malware Exploits Wireless ADB for Shell Access

A new variant of the RedHook Android malware leverages the Android Wireless Debugging (Wireless ADB) feature to achieve shell-level access on infected devices without connecting to a computer via USB. This novel approach marks a shift in how RedHook gains privileged access on Android systems.

What happened

Researchers have identified that the latest version of the RedHook Android malware abuses the Wireless ADB capability introduced in newer Android versions. Traditionally, gaining shell access through ADB required a physical USB connection to a trusted computer. RedHook's updated method circumvents this limitation by exploiting Wireless ADB, allowing it to execute shell commands remotely without user consent or direct device connection.

This technique enables the malware to escalate privileges more efficiently, increasing the potential for system manipulation and persistence on compromised Android devices.

Why it matters

The exploitation of Wireless ADB by malware is significant because this feature was designed primarily for developer convenience and secure wireless debugging. RedHook’s novel misuse of Wireless ADB removes the need for physical access or USB tethering, broadening the attack surface and simplifying privilege escalation.

This development challenges existing assumptions about the security boundaries of Android’s debugging features and highlights the necessity for enhanced controls around wireless debugging capabilities on mobile devices.

What security teams should do

Security teams should verify that Wireless Debugging is disabled on all devices unless explicitly required for development or maintenance. Regular audits of device configurations can help detect unauthorized enabling of Wireless ADB.

Additionally, monitoring network traffic for unusual usage patterns related to Wireless ADB ports may assist in early detection of exploitation attempts. Maintaining updated antivirus and endpoint protection tools on Android devices is also recommended.

Key technical details

RedHook’s new variant leverages Wireless ADB, a feature allowing ADB commands over a Wi-Fi connection rather than USB. This method permits the malware to establish a shell-level session remotely, bypassing previously necessary physical connections.

By abusing Wireless ADB, RedHook gains elevated privileges, allowing it to issue shell commands that can manipulate the device, potentially leading to data theft, persistence, or further malware deployment. The approach is notable as it uses legitimate Android debugging protocols in unintended ways.

Affected organizations/products

The malware targets Android devices that have Wireless Debugging enabled. Specific device models or Android versions affected have not been detailed. The abuse of Wireless ADB suggests that any device with this feature active is potentially vulnerable.

Source attribution

https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!