Red Alert 2.0

MITRE ATT&CK: S0539 View on attack.mitre.org

Aliases: Red Alert 2.0

Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:27:59

Targeted industries: financial-services

Targeted regions: country_code:us country_code:gb country_code:de

Context

Red Alert 2.0 is a banking trojan that masquerades as a VPN client.

Malware & tools used

  • Download New Code at Runtime (attack-pattern)
  • SMS Control (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Contact List (attack-pattern)
  • SMS Messages (attack-pattern)
  • Device Administrator Permissions (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Web Protocols (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Call Log (attack-pattern)
  • Software Discovery (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0539 (report)
  • news.sophos.com — Red Alert 2 0 Android Trojan Targets Security Seekers (report)

External references