RedAlert2

First seen
2018-07-01 00:00:00
Malware type
credential-stealer, trojan
Family
Malware family
Last IoC activity
2026-05-08 12:58:22
Profile updated
2026-07-07 14:09:20

Targeted industries: financial-services

Context

RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps. The malware works by overlaying a login screen with a fake display that sends the credentials to a C2 server. The malware also has the ability to block incoming calls from banks, to prevent the victim of being notified. As a distribution vector RedAlert 2 uses third-party app stores and imitates real Android apps like Viber, Whatsapp or fake Adobe Flash Player updates.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Redalert2 (report)
  • Trend Micro — Red Alert 2 0 Android Trojan Spreads Via Third Party App Stores (report)
  • threatfabric.com — New Android Trojan Targeting Over 60 Banks And Social Apps (report)

External references