RedHook
Malware family · 2 sample(s) · 6 indicator record(s) · 2 signing certificate(s) · Active 2026-07-23 → 2026-08-13 (experimental)
About RedHook
RedHook is an Android banking trojan / RAT (reported targeting Vietnamese users) that abuses Accessibility services for overlay credential capture, keylogging and remote control. Its C2 lives on a single registrable domain fronting many API subdomains (the *.3n7wj.com cluster: api, skt, sktv, sonxndskt, dlkxnxapi, eonxjdsktv) used for command polling and exfiltration.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| api.3n7wj.com | domain | 41742d12ee35… | 2026-07-23 |
| dlkxnxapi.3n7wj.com | domain | cc628150428e… | 2026-08-13 |
| eonxjdsktv.3n7wj.com/ws/device | domain | cc628150428e… | 2026-08-13 |
| skt.3n7wj.com/ws/device | domain | 41742d12ee35… | 2026-07-23 |
| sktv.3n7wj.com/ws/device | domain | 41742d12ee35… | 2026-07-23 |
| sonxndskt.3n7wj.com/ws/device | domain | cc628150428e… | 2026-08-13 |