RedWing Android Spyware Sold as a Service on Telegram
2026-07-08T20:52:14Z•c3c1a5b03e0e4d121e2c5a857c5609866a55d10d8546bc0e7fc5bc5cbe520817
Adobe ColdFusion (CVSS 10.0)Cavern ManticoreDjinn StealerJadePufferMillenium RATOracle PeopleSoft zero-dayOusabanPureLogQilinRedWingRoundcube exploitsScattered SpiderSimpleHelp RMM exploitTaskWeaverTelegram distributionTinyRCTUAT-7810VidarXMRigagentic AIbotnets/NetNut/Popafileless malwarephishingprompt injectionproxy/relay networks
What happened
Multiple high-impact active threats and exploitation campaigns were reported: an Android spyware-as-a-service called RedWing is being sold via Telegram to target banking apps; researchers observed agentic AI accelerating cloud compromises (Sygnia) and the first agentic ransomware (JadePuffer); China-linked APTs expanded proxy/backdoor infrastructure (UAT-7810, TinyRCT); large-scale malware campaigns include Millenium RAT (Telegram distribution), Vidar infostealer paired with XMRig miners, PureLog fileless infostealer via Blogspot, and the Ousaban banking trojan targeting Iberia. Several zero‑/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- c3c1a5b03e0e4d121e2c5a857c5609866a55d10d8546bc0e7fc5bc5cbe520817
- Enrichment time
- 2026-07-08T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.