Technology

Malicious Program RedWing Stealer Targets 12 Banks of Uzbekistan

Illustration: Tezkun / AI. Not a photograph of the event.

Clients of 12 banks in Uzbekistan have been targeted by a new version of the RedWing Stealer malware for Android.

Clients of 12 banks in Uzbekistan have been targeted by a new version of the RedWing Stealer malware for Android, according to researchers at F6. From May to September 2026, the specialists identified over 800 samples of the program. In addition to Uzbek banks, the malware targets clients of 16 Russian and seven Kazakh banks, as well as nine Russian marketplaces and eight microfinance organizations. The names of the 12 financial institutions in Uzbekistan are not disclosed in the report, and data on affected users in the country and the amount of damage are not provided.

The program masquerades as third-party APK files, including VPN services, media file viewers, and mobile game modification tools. After launch, the application requests access to SMS processing, autostart, and background operation, and then prompts the user to enter a PIN code, sending it to a remote server. The program can intercept notifications and messages from banking services, collect contact, location, and SIM card information, perform USSD requests, send SMS, and hide its icon.

F6 recommends refusing to download APK files from unofficial sources, checking requested permissions, and not providing personal data in suspicious forms. In case of infection, experts advise removing the application, checking the system with security software, changing passwords from another device, and blocking the card through the bank if there is a risk of compromise.

Published 8 October 2026, 23:02 · No updates · Russian original

Discussion
  1. Loading comments…
No links or insults. One comment per 20 seconds.

Comments on this story live under its post in our Telegram channel. Comment on Telegram