Story perspectives
RedHook Android Malware Exploits Wireless Debugging, Streams Screens, Captures Keystrokes
7/21/2026
1 of 1
Story summary
- RedHook Android malware exploits Wireless Debugging to gain privileges after victims sideload a malicious APK via social-engineering messages.
- It reads the debugging code and connects through 127.0.0.1, granting screen streaming and keystroke capture.
- RedHook stays alive with silent audio, a WakeLock, an alarm and two services that restart each other after reboot.
- Experts recommend installing apps from Google Play, disabling unknown-app installs for browsers and messaging, and enabling Play Protect.
