Cybersecurity researchers have identified an upgraded Android malware called RedHook that can seize extensive control of a device after a single, misguided permission approval.

The attack begins with social engineering. Criminals impersonate bank or government officials, directing victims to fake websites that mimic Google Play. Victims are tricked into installing an app from outside the official store and then guided to enable Accessibility services.

Once enabled, RedHook exploits Android's Wireless Debugging feature, introduced in Android 11. It tricks the phone into connecting to its own powerful debugging controls locally, gaining shell-level privileges.

This allows the malware to stream the screen, record keystrokes, capture credentials, simulate taps, install or remove apps without prompts, and activate the camera. It also employs persistence techniques like silent audio playback and service monitoring to avoid being shut down.

Experts urge users to install apps only through Google Play, treat Accessibility requests as highly sensitive, and keep Google Play Protect enabled. Suspicious requests for immediate action should be verified through official channels.