Malicious RedHook Android RAT C2 REST Endpoint Access (via proxy)

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

What it detects

This rule detects HTTP requests to the RedHook Android RAT command-and-control REST endpoints addDevicePassword and addsKeyboardInput used to upload stolen device credentials and keylogged input. These distinctive server paths identify infected mobile devices beaconing to attacker infrastructure. Detection reveals active data theft from compromised Android hosts.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.