SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, July 13, 2026 INTEL CONFIDENCE 64% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY RedHook Android Malware Abuses Wireless ADB Shell | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 4 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by a significant evolution in mobile threats, with the RedHook Android malware now abusing the Wireless ADB mechanism to gain unauthorized shell-level privileges on target devices. Concurrently, major AI vendors OpenAI and Anthropic have adjusted usage limits and access timelines for their flagship models, GPT-5.6 Sol and Claude Fable 5, to manage surging user demand. Security teams should immediately audit corporate Android fleets to ensure developer options and wireless debugging are disabled. |
|
■ CRITICAL STORIES RedHook Android malware now uses Wireless ADB for shell access A new variant of the RedHook Android malware has been observed abusing the Android Wireless Debugging (Wireless ADB) mechanism to gain high-privilege shell access on devices without needing a physical USB connection. |
OpenAI temporarily relaxes GPT-5.6 Sol usage limits OpenAI has temporarily increased usage caps for its GPT-5.6 Sol model following a massive 48-hour spike in global demand. |
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time Anthropic has extended free access to its Claude Fable 5 model for paid subscribers to July 19 while managing infrastructure capacity. |
|
■ CVEs IDENTIFIED [CVE-TBD] Google Android — Privilege escalation via unauthorized Wireless ADB shell access abuse by RedHook malware. |
|
■ THREAT ACTORS RedHook Operators | Cybercrime |
Distributing and updating the RedHook Android malware to exploit Wireless ADB for elevated privileges. |
|
|
|
■ ATT&CK TTPs | T1059.006 | | Command and Scripting Interpreter: Android Command Shell | RedHook malware executes commands via the Wireless ADB shell. |
| T1548 | | Abuse Elevation Control Mechanism | RedHook bypasses standard permission prompts to obtain shell-level privileges. |
| T1021 | | Remote Services | Abuse of Wireless ADB for remote/local device management and command execution. |
|
■ PATCH PRIORITY Google Android — Disable Wireless ADB to prevent RedHook privilege escalation (PE) — BleepingComputer |
OpenAI GPT-5.6 Sol — Monitor API usage and rate limits — BleepingComputer |
Anthropic Claude Fable 5 — Monitor access and data exposure risks — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Disable "Wireless Debugging" and "USB Debugging" in Android Developer Options on all corporate-enrolled Android devices to mitigate [CVE-TBD] (RedHook Wireless ADB abuse). |
| 2 | [P2] Implement Mobile Device Management (MDM) policies to block or restrict access to "Developer Options" on enterprise Android devices. |
| 3 | [P3] Monitor network traffic for anomalous outbound connections on port 5555 or dynamic ports associated with Android Wireless ADB. |
| 4 | [P3] Audit enterprise API usage of OpenAI GPT-5.6 Sol and Anthropic Claude Fable 5 to ensure data privacy boundaries are maintained during high-demand periods. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |