Your phone rings, and the caller sounds official. They say your bank account or government service needs immediate verification. A link arrives moments later. The page looks like Google Play, and the caller tells you to install an app to fix the problem. Then the app asks you to turn on Accessibility access, a powerful Android permission that can let an app read the screen and control taps.That approval can give the latest RedHook Android malware far more control than a regular app should have. Researchers at Group—IB, a global cybersecurity company that investigates online fraud and digital crime, analyzed the new threat. They say the upgraded remote access trojan, a type of malware that lets criminals control a device remotely, abuses Android’s Wireless Debugging feature to gain shell-level privileges. That means it can run powerful system commands and change protected settings that ordinary apps cannot access, although it does not gain full root control.RedHook can then watch the screen, record what you type, operate apps and steal login information. The new technique also helps it install or remove apps without showing the usual approval prompts. That makes one rushed permission decision especially costly.Free live CyberGuy class: Sick of Spam? Join us July 22Join us Wednesday, July 22, at 1 p.m. ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.Reserve your free spot today at CyberGuyLive.com.NEW BANK SCAM LAWS COULD STOP SUSPICIOUS PAYMENTSThe attack begins with social engineering. Criminals call or message victims while posing as bank employees, government representatives or support agents. They direct people to fake websites that resemble official services or the Google Play Store. However, the app comes from outside Google Play. The victim sideloads an APK, which means installing an Android app from another source. After installation, the app guides the victim through enabling Accessibility.Android built Accessibility services to help people use their devices. However, those services can also let an approved app observe the screen and perform actions for the user. RedHook takes advantage of that control. It simulates taps, opens Settings and enables Developer Options. Next, it turns on Wireless Debugging and asks Android for a pairing code.The malware reads the code and connects back to the phone through 127.0.0.1, a local address that points to the same device. In effect, RedHook tricks the phone into connecting to its own powerful debugging controls, giving the malware deeper access without a computer.ADB stands for Android Debug Bridge. Developers use it to manage a phone from a command line, install test apps and troubleshoot software. Android introduced Wireless Debugging with Android 11, allowing ADB connections over Wi-Fi instead of a USB cable. Once RedHook pairs with the phone, it gains shell-level access. That gives the malware more authority than a normal Android app, allowing it to run powerful commands and change protected settings. However, it still does not gain full root control.RedHook can then grant itself additional permissions, capture low-level touch activity and avoid some confirmation screens that would normally alert the user. The malware also borrows from Shizuku, a legitimate Android utility used by developers and power users. Shizuku allows approved apps to use elevated Android features without rooting a phone. RedHook repurposes parts of that framework to carry out malicious commands.Group-IB counted 53 commands that attackers can send to the current RedHook version. Some commands appear unfinished, but the working features give criminals extensive access to an infected phone.That access creates several opportunities for fraud. A criminal could watch you sign in to a banking app, capture a verification code or place a convincing overlay above a real login screen. RedHook may also remove security software or install another malicious app.Gaining access helps the attacker only while the malware remains active. Therefore, RedHook includes several persistence methods designed to keep Android from shutting it down. It can play silent audio so the operating system treats its process as important. A WakeLock keeps the CPU awake. Meanwhile, two separate services monitor each other and restart their partner when one stops.RedHook also sets a five-minute alarm that checks whether its services remain alive. After a reboot, a receiver can restart the malware and reconnect its privileged helper. It even adjusts its out-of-memory score to reduce the chance that Android will close it when memory runs low. These methods make removal harder. They also explain why simply swiping the app away may accomplish very little.One warning sign may have an innocent explanation. Several appearing together should make you stop and investigate.Do not let an urgent tone make the decision for you. Legitimate organizations can give you time to verify a request through an official phone number or website.AMAZON RECALL TEXT SCAM COMES WITH RED FLAGSA few checks can stop this attack before it reaches the Wireless Debugging stage. Other steps can help limit the damage if you already installed a suspicious app.Settings may vary depending on your Android phone’s manufacturerAvoid APK files sent through texts, messaging apps or unexpected phone calls. Apps downloaded from unknown sources can put your device and personal information at risk. You should also review which apps can install software from outside Google Play. Open Settings and search for Install unknown apps . Turn off this permission for browsers, messaging apps and file managers unless you have a specific reason to use it.Hang up and call the organization using the number printed on your bank card or listed on its official website. Avoid phone numbers included in the message, pop-up or download page. Be especially cautious when someone contacts you unexpectedly and pressures you to change a phone setting or install an app. Google lists both behaviors as warning signs of a possible scam.Open Settings and search for Accessibility . Then review Installed apps , Downloaded apps or Installed services , depending on your phone. Turn off access for anything you do not recognize. An ordinary banking, delivery or government app rarely needs permission to read your screen and control your taps. Pause whenever an app claims that Accessibility access is required to complete verification. As CyberGuy has previously reported, malware can abuse Accessibility permissions to take control of an Android phone.Open the Google Play Store > tap your profile icon > Play Protect . Tap Scan to check the apps currently installed on your phone. Play Protect may warn you about harmful software, which you can disable or remove from the phone. Google Play Protect, which is built-in malware protection for Android devices, automatically removes known malware. However, Play Protect may not catch every malicious app, so strong antivirus software adds another layer of protection.Strong antivirus software can help flag malicious links, suspicious downloads and harmful apps. Keep its protection active, especially if you sometimes receive APK files for work or testing. However, do not assume an antivirus scan has fully removed RedHook if the app keeps returning or your settings continue to change. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.comOpen Settings > Software updates , then follow the prompts. You can also check your Android security update and Google Play system update under About phone > Android version . Paths can differ slightly by device.Turn on Airplane mode and use another trusted device to contact your bank and change important passwords. Do not enter more information on the affected phone. Try to remove the suspicious app or contact your phone manufacturer, carrier or a trusted repair professional for help. A factory reset may be necessary if the app returns or the phone continues behaving strangely.A data removal service can help reduce the personal details available about you on people-search sites. That may include your home address, phone number and information about relatives. However, a data removal service cannot clean malware from your phone, recover stolen login information or remove data that criminals already copied. You can also submit opt-out requests yourself for free, although the process can take time. Information may later reappear, so continued monitoring may be needed. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.comHALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTERRedHook depends on social engineering before it can take control. The attacker still needs you to install a malicious app and approve powerful Accessibility permissions. That gives you a chance to stop the attack early. Be suspicious of urgent calls, fake app pages and anyone who tells you to install an APK from a link. Google Play Protect and strong antivirus software can help, but your best defense is slowing down before you approve an unexpected request.Should Android make Accessibility permissions harder to approve when an app comes from outside Google Play? Let us know by writing to us at Cyberguy.com.Sign up for my FREE CyberGuy ReportCopyright 2026 CyberGuy.com. All rights reserved.