RedHook and Hook v3: Banking Trojans with Remote Access
A new wave of cyber attacks is sweeping across Germany and Europe, bringing sophisticated malware in its wake. The security firm Group-IB has issued a warning about a new variant of the RedHook Trojan. This malicious software exploits the Android Wireless Debugging feature (ADB) to gain remote access to infected devices. Attackers can steal banking credentials and take control of victims’ smartphones with alarming ease.
Taking it a step further, Hook v3 was identified by Zimperium zLabs over the weekend. This latest version of the banking Trojan supports a whopping 107 remote control commands—38 of which are entirely new. The malware is disseminated through phishing campaigns and malicious GitHub repositories.
Some of its alarming capabilities include:
- Fake NFC and credit card overlays to intercept payment data.
- Real-time bypassing of lock screens.
- Ransomware functions aimed at extorting victims.
DroidLock: Ransomware Targeting Spanish Users
Simultaneously, researchers have discovered a targeted ransomware campaign known as DroidLock. Primarily aimed at users in Spain, this malware employs techniques that could easily spill over into other countries.
DroidLock abuses Android’s accessibility services to gain complete control over a device. The program can execute 15 different commands, ranging from locking the device and changing the PIN to wiping all data. Victims receive an extortion message with a 24-hour deadline.
Android 16: Gemini Vulnerability Poses Message Risks
A critical bug in Android 16 adds to the growing concerns. This flaw allows the AI assistant Gemini to send messages while the smartphone is locked. Although attackers need physical access, they can bypass the lock screen using a multi-touch gesture.
The vulnerability allows for:
- Unauthorized sending of SMS and WhatsApp messages.
- Restoration of Gemini permissions.
- Access to and deletion of chat histories.
- Changes to security settings.
AI Hallucinations as a Breach Point
A particularly insidious attack method called HalluSquatting has emerged. Criminals exploit AI assistants’ known weaknesses, which often generate non-existent software names—referred to as hallucinations.
The tactic involves attackers registering these fictitious repository names and filling them with malicious code. Developers and researchers, trusting AI, unwittingly download the malware. Test results have shown that the hallucination rate across various AI platforms can reach as high as 85%.
Immediate Protective Measures Recommended
The current threat landscape resembles past attack waves, with earlier malware like Gooligan infecting over a million Android accounts at a staggering growth rate of 13,000 devices per day. Experts warn that RedHook and Hook v3 are technically even more dangerous and could reach similar scales.
After several high-profile WhatsApp hacks—some involving politicians—security experts urge immediate action. If theft or hacking is suspected:
- Immediately disable your SIM card.
- Perform a remote wipe of your device.
- Secure your bank accounts and email.
To prevent future attacks, experts recommend:
- Activating multi-factor authentication.
- Utilizing WhatsApp passkeys.
- Regularly reviewing app permissions.
In light of these developments, a basic level of smartphone protection has become essential for securing online banking and sensitive data.

