Portrait of a cybersecurity expert commenting on the RedHook Android malware that exploits the developer (ADB) setting to bypass MFA and drain bank accounts.
Expert on the RedHook Android malware abusing developer settings to bypass MFA.

That Android setting you never touch? Malware is using it to empty bank accounts

That Android setting you never touch? Hackers are using it to bypass your MFA and empty your bank account. Here is how the new RedHook malware takes over your phone 👇 #Android #Cybersecurity #TechNews


Advertisements

MANILA, Philippines (July 2026) – A hidden feature inside your Android phone that you probably never knew existed is being used by hackers to drain bank accounts and take absolute control of devices.

The malware, known as RedHook, is a newly upgraded strain that exploits a specific developer setting: the Wireless Android Debug Bridge, or ADB.

According to Shane Barney, Chief Information Security Officer of Keeper Security, the attack does not even need to exploit a traditional software vulnerability to succeed. Instead, it relies on tricking the user.

How the trap works

The attack begins when a victim is tricked into enabling accessibility permissions on their phone. Once these permissions are granted, RedHook silently turns on the Wireless ADB tool. This gives the malware shell-level privileges, essentially giving the attacker total access to the device.

At that point, stealing banking credentials becomes effortless. The attacker owns the entire session, meaning they can see every keystroke you make and everything on your screen.

Barney warned that even multi-factor authentication, or MFA, cannot save users once a device is compromised at this level. While MFA secures the initial login, it does nothing once an attacker has hijacked the session on the device itself.

Not just a regional threat

So far, security researchers have spotted active campaigns concentrated in Vietnam and Indonesia. However, Barney pointed out that the technique is not restricted by geography because it exploits features built into every single Android device on the market.

Historically, mobile banking malware that succeeds in one country eventually spreads to other regions.

This poses a massive risk not just for everyday Pinoy smartphone users, but also for organizations. Any company that allows employees to use unmanaged personal devices for work is highly exposed. A full device compromise means attackers can steal corporate login credentials, session tokens and sensitive data stored on the phone.

How to stay safe

To defend against this threat, continuous verification of endpoints and user sessions is necessary. Relying on MFA as a single line of defense is no longer enough. Security experts recommend that organizations immediately audit which personal devices are allowed to access corporate networks, while everyday users should be extremely cautious about what permissions they grant to newly downloaded apps.


What's Your Reaction?

Wakeke Wakeke
0
Wakeke
BULOK! BULOK!
0
BULOK!
Aww :( Aww :(
0
Aww :(
ASTIG! ASTIG!
0
ASTIG!
AMP#*@! AMP#*@!
0
AMP#*@!
Nyeam! Nyeam!
0
Nyeam!
ASTIG PH Team

Pinoy experiences online. A community dedicated to serving the best stories from the Philippines to the rest of the world. Want to work with us?