Daily Security Intel

Archives
Log in
Subscribe
July 13, 2026

[SecurityIntel] 13 Jul | RedHook Android Malware Abuses Wireless ADB Shell

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, July 13, 2026

INTEL CONFIDENCE  64%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

RedHook Android Malware Abuses Wireless ADB Shell

CRITICAL

5

C2 IPs

0

OTX IOCs

4

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by a significant evolution in mobile threats, with the RedHook Android malware now abusing the Wireless ADB mechanism to gain unauthorized shell-level privileges on target devices. Concurrently, major AI vendors OpenAI and Anthropic have adjusted usage limits and access timelines for their flagship models, GPT-5.6 Sol and Claude Fable 5, to manage surging user demand. Security teams should immediately audit corporate Android fleets to ensure developer options and wireless debugging are disabled.

■ CRITICAL STORIES

CRITICAL#1

RedHook Android malware now uses Wireless ADB for shell access

A new variant of the RedHook Android malware has been observed abusing the Android Wireless Debugging (Wireless ADB) mechanism to gain high-privilege shell access on devices without needing a physical USB connection.

INFO#2

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

OpenAI has temporarily increased usage caps for its GPT-5.6 Sol model following a massive 48-hour spike in global demand.

INFO#3

Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time

Anthropic has extended free access to its Claude Fable 5 model for paid subscribers to July 19 while managing infrastructure capacity.

■ CVEs IDENTIFIED

[CVE-TBD]

Google Android — Privilege escalation via unauthorized Wireless ADB shell access abuse by RedHook malware.

Critical

■ THREAT ACTORS

RedHook Operators

Cybercrime

Distributing and updating the RedHook Android malware to exploit Wireless ADB for elevated privileges.

■ ATT&CK TTPs

T1059.006
Command and Scripting Interpreter: Android Command Shell | RedHook malware executes commands via the Wireless ADB shell.
T1548
Abuse Elevation Control Mechanism | RedHook bypasses standard permission prompts to obtain shell-level privileges.
T1021
Remote Services | Abuse of Wireless ADB for remote/local device management and command execution.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Google Android — Disable Wireless ADB to prevent RedHook privilege escalation (PE) — BleepingComputer

[P3 PATCH NOW]≤1 week

OpenAI GPT-5.6 Sol — Monitor API usage and rate limits — BleepingComputer

[P3 PATCH NOW]≤1 week

Anthropic Claude Fable 5 — Monitor access and data exposure risks — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Disable "Wireless Debugging" and "USB Debugging" in Android Developer Options on all corporate-enrolled Android devices to mitigate [CVE-TBD] (RedHook Wireless ADB abuse).
2[P2] Implement Mobile Device Management (MDM) policies to block or restrict access to "Developer Options" on enterprise Android devices.
3[P3] Monitor network traffic for anomalous outbound connections on port 5555 or dynamic ports associated with Android Wireless ADB.
4[P3] Audit enterprise API usage of OpenAI GPT-5.6 Sol and Anthropic Claude Fable 5 to ensure data privacy boundaries are maintained during high-demand periods.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 14 Jul | Active Exploitation of Joomla RCE and Zimbra Flaws Older → [SecurityIntel] 12 Jul | Compromised Jscrambler NPM Package Drops Rust Infostealer
Powered by Buttondown, the easiest way to start and grow your newsletter.