A newfound Android Malware as a Service has been discovered—a variant of the older Oblivion tool being rented out on Telegram for 300 dollars a month. The product is called RedWing, a package of builders and droppers that use phishing campaigns to infiltrate Android targets and ultimately steal bank credentials. The payload is downloaded from a fake app-store page, and after enabling several accessibility settings and granting permissions, the user is left with an infected phone. The malware deploys login overlays that mimic official bank apps in order to steal passwords. SMS and calling access complete with keyloggers guarantees that victims stay in the dark as their bank accounts are emptied.