Hanoi Police today issued a warning about two highly dangerous malware strains, RedHook spyware and StormEncryptor ransomware, which can seize "supreme control" over mobile phones and computer systems. The investigation agency stated that the malware targets government agency systems and the mobile devices of officials, public servants, and workers across the capital.
RedHook spyware
The RedHook spyware strain, first detected in early August, represents a new, dangerous generation. This malware specifically targets mobile devices running the Android operating system. RedHook primarily spreads through fake SMS messages and over-the-top (OTT) messaging applications like Zalo and Telegram.
The malware also propagates via websites impersonating the National Public Service Portal, the Hanoi Public Service Portal, the eTax Mobile application, the VNeID application, and major commercial banks.
RedHook's technical modus operandi involves abusing accessibility services. Immediately after a user downloads and installs a malicious ".APK" file, the malware employs deceptive interface tactics to request "accessibility services" permissions. If granted, RedHook gains "supreme control" over the user interface without needing to root the device.
Moreover, if automatically granted system permissions, the malware silently performs touch operations to acquire all other critical permissions. These include reading and sending SMS, accessing contacts, call logs, storage, recording audio, and drawing overlays on the screen.
The intrusive malware also steals data and conducts real-time monitoring by covertly recording the screen, logging keystrokes, secretly reading messages containing one-time password (OTP) verification codes, bank account passwords, and sensitive personal data. The malware can also automatically activate legitimate banking applications on the victim's phone, initiate transfer commands, auto-fill OTPs, and approve transactions without the victim's knowledge.
The RedHook spyware strain can automatically reactivate all its malicious processes, even if the user restarts their phone.
![]() |
Hanoi Police recommendations. Photo: Public security provided. |
StormEncryptor ransomware
The StormEncryptor ransomware, detected on 11/8, was deployed by the professional hacker group Storm-1175. It targets all Windows server systems and Windows clients within the internal networks of agencies and businesses.
StormEncryptor employs three primary infection and damage methods. One is a supply chain attack via remote monitoring and management (RMM) tools. Hackers exploit a critical security vulnerability in the N-able N-central remote system monitoring and management platform to seize supreme administrative control of the centralized management hub.
Two is automatic widespread malware infection. From the compromised N-central server, hackers utilize the system's own automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period.
Three is double encryption and extortion. The malware stops security services, deletes backup copies, and then encrypts all data files using a strong encryption algorithm, leaving a ransom note. Simultaneously, hackers extract and steal sensitive data before encryption, threatening to publish it.
Immediately disable Wi-Fi, 5G if malware detected
Hanoi Police advise that if a mobile device shows signs of RedHook infection, users must immediately isolate the network, refrain from entering any more passwords or OTPs, and use another clean device to call the bank hotline to freeze accounts at once.
Signs of infection include the appearance of unfamiliar applications, automatic screen jumps, unexplained loss of money, the device becoming unusually hot when not in use, the screen operating by itself, or the appearance of a "wireless debugging" notification.
Additionally, if StormEncryptor or RedHook malware is detected, police recommend immediately turning off Wi-Fi, 3G/4G/5G on mobile devices, or disconnecting network cables/VLANs for computers. Users must absolutely not restart servers without first backing up RAM.
Furthermore, users should use another clean device to change passwords and PINs, and immediately contact their bank to block accounts and cards. After these steps, a clean operating system should be reinstalled, all security vulnerabilities patched, and data restored from a secure offline backup.
To protect themselves, police advise users to never click on suspicious links sent via email, SMS, Zalo, or other OTT applications. Individuals should not download or install applications from unknown sources, especially ".APK" files on Android phones, and should not open or extract strange attachments.
