RedHook

Malware family · 2 sample(s) · 6 indicator record(s) · 2 signing certificate(s) · Active 2026-07-23 → 2026-08-13 (experimental)

About RedHook

RedHook is an Android banking trojan / RAT (reported targeting Vietnamese users) that abuses Accessibility services for overlay credential capture, keylogging and remote control. Its C2 lives on a single registrable domain fronting many API subdomains (the *.3n7wj.com cluster: api, skt, sktv, sonxndskt, dlkxnxapi, eonxjdsktv) used for command polling and exfiltration.

Indicators

IndicatorTypeSampleFirst seen
api.3n7wj.com domain 41742d12ee35… 2026-07-23
dlkxnxapi.3n7wj.com domain cc628150428e… 2026-08-13
eonxjdsktv.3n7wj.com/ws/device domain cc628150428e… 2026-08-13
skt.3n7wj.com/ws/device domain 41742d12ee35… 2026-07-23
sktv.3n7wj.com/ws/device domain 41742d12ee35… 2026-07-23
sonxndskt.3n7wj.com/ws/device domain cc628150428e… 2026-08-13