RedAlert2
- First seen
- 2018-07-01 00:00:00
- Malware type
- credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-05-08 12:58:22
- Profile updated
- 2026-07-07 14:09:20
Targeted industries: financial-services
Context
RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps. The malware works by overlaying a login screen with a fake display that sends the credentials to a C2 server. The malware also has the ability to block incoming calls from banks, to prevent the victim of being notified. As a distribution vector RedAlert 2 uses third-party app stores and imitates real Android apps like Viber, Whatsapp or fake Adobe Flash Player updates.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Redalert2 (report)
- Trend Micro — Red Alert 2 0 Android Trojan Spreads Via Third Party App Stores (report)
- threatfabric.com — New Android Trojan Targeting Over 60 Banks And Social Apps (report)