What happened
Security researchers at Zimperium's zLabs have identified a malware-as-a-service operation dubbed RedWing, available for rent on Telegram and believed to be an evolution of the earlier Oblivion toolkit, which previously sold for around $300 a month. RedWing gives buyers the ability to seize control of Android devices, harvest banking credentials, and intercept the one-time passcodes that would otherwise block unauthorized account access — no advanced technical skills required. Separately, the FBI announced the seizure of hundreds of domains tied to NetNut, a residential proxy service run by publicly traded Israeli firm Alarum Technologies. The action followed reporting by KrebsOnSecurity that linked NetNut to the Popa botnet, a network of compromised devices used to route malicious traffic.
Why it matters for your business
The commoditization of Android bank-fraud tools means threat actors no longer need deep expertise to target employees or customers who use mobile banking apps — the barrier to entry is now a Telegram subscription. Organizations that rely on SMS-based two-factor authentication face elevated risk, since RedWing is specifically engineered to capture those codes. The NetNut seizure underscores that even legitimate-looking, publicly traded proxy providers can serve as infrastructure for criminal operations, complicating vendor due diligence processes. Security and procurement teams should audit any third-party proxy or residential IP services in their supply chains and accelerate migration away from SMS-based authentication toward hardware tokens or passkeys.
What to watch next
Analysts will be monitoring whether RedWing's Telegram distribution model spawns copycat MaaS offerings targeting other mobile platforms, particularly as Android's global market share makes it a high-value target. The Alarum Technologies case is likely to prompt regulatory and investor scrutiny of other publicly traded firms whose infrastructure is found to overlap with botnet activity. Any indictments or civil actions stemming from the FBI's NetNut seizure could set a precedent for corporate liability when a commercial proxy service is tied to organized cybercrime.
