RedWing Android Spyware Sold as a Service on Telegram

2026-07-08T20:52:14Zc3c1a5b03e0e4d121e2c5a857c5609866a55d10d8546bc0e7fc5bc5cbe520817
Adobe ColdFusion (CVSS 10.0)Cavern ManticoreDjinn StealerJadePufferMillenium RATOracle PeopleSoft zero-dayOusabanPureLogQilinRedWingRoundcube exploitsScattered SpiderSimpleHelp RMM exploitTaskWeaverTelegram distributionTinyRCTUAT-7810VidarXMRigagentic AIbotnets/NetNut/Popafileless malwarephishingprompt injectionproxy/relay networks

What happened

Multiple high-impact active threats and exploitation campaigns were reported: an Android spyware-as-a-service called RedWing is being sold via Telegram to target banking apps; researchers observed agentic AI accelerating cloud compromises (Sygnia) and the first agentic ransomware (JadePuffer); China-linked APTs expanded proxy/backdoor infrastructure (UAT-7810, TinyRCT); large-scale malware campaigns include Millenium RAT (Telegram distribution), Vidar infostealer paired with XMRig miners, PureLog fileless infostealer via Blogspot, and the Ousaban banking trojan targeting Iberia. Several zero‑/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
c3c1a5b03e0e4d121e2c5a857c5609866a55d10d8546bc0e7fc5bc5cbe520817
Enrichment time
2026-07-08T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · RedWing Android Spyware Sold as a Service on Telegram · Baitaphish