Eng English
China 中国人

Eng English
China 中国人
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Law
  • Education
  • Health
  • Lifestyle
  • Travel
  • Science
  • Digital
  • Automobiles
  • Trở lại Thể thao
  • Law
Wednesday, 26/8/2026 | 11:58 GMT+7

Police uncover highly dangerous malware with 'supreme control' over mobile phones

Hanoi police detect highly dangerous RedHook spyware and StormEncryptor ransomware capable of gaining 'supreme control' over user phones.

Hanoi Police today issued a warning about two highly dangerous malware strains, RedHook spyware and StormEncryptor ransomware, which can seize "supreme control" over mobile phones and computer systems. The investigation agency stated that the malware targets government agency systems and the mobile devices of officials, public servants, and workers across the capital.

RedHook spyware

The RedHook spyware strain, first detected in early August, represents a new, dangerous generation. This malware specifically targets mobile devices running the Android operating system. RedHook primarily spreads through fake SMS messages and over-the-top (OTT) messaging applications like Zalo and Telegram.

The malware also propagates via websites impersonating the National Public Service Portal, the Hanoi Public Service Portal, the eTax Mobile application, the VNeID application, and major commercial banks.

RedHook's technical modus operandi involves abusing accessibility services. Immediately after a user downloads and installs a malicious ".APK" file, the malware employs deceptive interface tactics to request "accessibility services" permissions. If granted, RedHook gains "supreme control" over the user interface without needing to root the device.

Moreover, if automatically granted system permissions, the malware silently performs touch operations to acquire all other critical permissions. These include reading and sending SMS, accessing contacts, call logs, storage, recording audio, and drawing overlays on the screen.

The intrusive malware also steals data and conducts real-time monitoring by covertly recording the screen, logging keystrokes, secretly reading messages containing one-time password (OTP) verification codes, bank account passwords, and sensitive personal data. The malware can also automatically activate legitimate banking applications on the victim's phone, initiate transfer commands, auto-fill OTPs, and approve transactions without the victim's knowledge.

The RedHook spyware strain can automatically reactivate all its malicious processes, even if the user restarts their phone.

Hanoi Police recommendations. Photo: Public security provided.

StormEncryptor ransomware

The StormEncryptor ransomware, detected on 11/8, was deployed by the professional hacker group Storm-1175. It targets all Windows server systems and Windows clients within the internal networks of agencies and businesses.

StormEncryptor employs three primary infection and damage methods. One is a supply chain attack via remote monitoring and management (RMM) tools. Hackers exploit a critical security vulnerability in the N-able N-central remote system monitoring and management platform to seize supreme administrative control of the centralized management hub.

Two is automatic widespread malware infection. From the compromised N-central server, hackers utilize the system's own automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period.

Three is double encryption and extortion. The malware stops security services, deletes backup copies, and then encrypts all data files using a strong encryption algorithm, leaving a ransom note. Simultaneously, hackers extract and steal sensitive data before encryption, threatening to publish it.

Immediately disable Wi-Fi, 5G if malware detected

Hanoi Police advise that if a mobile device shows signs of RedHook infection, users must immediately isolate the network, refrain from entering any more passwords or OTPs, and use another clean device to call the bank hotline to freeze accounts at once.

Signs of infection include the appearance of unfamiliar applications, automatic screen jumps, unexplained loss of money, the device becoming unusually hot when not in use, the screen operating by itself, or the appearance of a "wireless debugging" notification.

Additionally, if StormEncryptor or RedHook malware is detected, police recommend immediately turning off Wi-Fi, 3G/4G/5G on mobile devices, or disconnecting network cables/VLANs for computers. Users must absolutely not restart servers without first backing up RAM.

Furthermore, users should use another clean device to change passwords and PINs, and immediately contact their bank to block accounts and cards. After these steps, a clean operating system should be reinstalled, all security vulnerabilities patched, and data restored from a secure offline backup.

To protect themselves, police advise users to never click on suspicious links sent via email, SMS, Zalo, or other OTT applications. Individuals should not download or install applications from unknown sources, especially ".APK" files on Android phones, and should not open or extract strange attachments.

By VnExpress: https://vnexpress.net/cong-an-phat-hien-ma-doc-dac-biet-nguy-hiem-kiem-soat-toi-cao-dien-thoai-di-dong-5113589.html
Tags: malware spyware ransomware dangerous malware cyber attack

News in the same category

Former commune chairman prosecuted for unauthorized riverbank land lease

Former commune chairman prosecuted for unauthorized riverbank land lease

Tran Van Tro, former chairman of Trung Ha Commune People's Committee in what was Vinh Phuc province, faces charges for allegedly leasing riverbank land to 8 households without authorization, with the actual occupied area exceeding the contracted amount by more than 7 times.

TikToker livestreams sale of fake Ngoc Linh ginseng

TikToker livestreams sale of fake Ngoc Linh ginseng

The owner of the TikTok account "Hang Le Sam Ngoc Linh" faces accusations of purchasing unregulated ginseng on the market, then falsely labeling it as authentic Kon Tum Ngoc Linh ginseng for livestream sales.

Assuming customer silence is consent for data processing could lead to a 70 million dong fine

Assuming customer silence is consent for data processing could lead to a 70 million dong fine

Businesses that automatically consider customer silence or non-response as "consent for personal data collection and processing" could face penalties of up to 70 million dong.

The mystery behind an officer's motive for faking 200 missing person reports

The mystery behind an officer's motive for faking 200 missing person reports

Officer Bu's colleagues could not find any reason to explain his faking about 200 reports, lying to missing persons' families to close cases.

Companies storing employee data beyond necessary periods face fines of up to 40 million dong

Companies storing employee data beyond necessary periods face fines of up to 40 million dong

Businesses retaining employees' personal data for longer than required for processing purposes could face penalties reaching 40 million dong.

Parents of girl sue badminton racket company after fatal playing incident

Parents of girl sue badminton racket company after fatal playing incident

The parents of a 6-year-old girl are suing a badminton racket manufacturer after a metal shaft detached from a racket during play, striking the girl in the brain and causing her death.

Clues Lead to Major Drug Ring Involving Actress Kieu Thanh

Clues Lead to Major Drug Ring Involving Actress Kieu Thanh

Police uncovered a major drug ring involving hundreds of individuals after an incident where suspects drove a car at officers and resisted arrest, leading to warning shots being fired.

Three former judges, prosecutors in Hue sentenced to prison for accepting bribes from defendants

Three former judges, prosecutors in Hue sentenced to prison for accepting bribes from defendants

Former Hue City People's Court judge Thai Thi Hong Van received a 500 million VND bribe to ensure two gambling defendants avoided prison sentences.

51 individuals arrested in 4,000 billion VND invoice trading case

51 individuals arrested in 4,000 billion VND invoice trading case

Vu Hai Dong Duong and 50 others are accused of trading approximately 24,000 invoices, with a total post-tax value of goods and services estimated at 4,000 billion VND.

Publicly exposing others' data could incur a 25 million dong fine

Publicly exposing others' data could incur a 25 million dong fine

Individuals who publicly disclose others' data without consent could face fines of up to 25 million dong and be required to remove or recall the published information.

Eng English
China 中国人
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Law
  • Education
  • Health
  • Lifestyle
  • Travel
  • Science
  • Digital
  • Automobiles
FPT Tower, 10 Pham Van Bach Street, Dich Vong Ward,
Cau Giay District, Hanoi, Vietnam
Email: contacts@vnportal.net
Tel: 028 7300 9999 - Ext 8556
Advertise with us: 090 293 9644
Register
© Copyright 2026 vnnow.net. All rights reserved.
Terms of use Privacy policy Cookies