Suspicious RedHook Android RAT WebSocket Device Channel (via proxy)

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-05-31
Updated
2026-08-28

What it detects

This rule detects WebSocket connections to the RedHook Android RAT device channel identified by the ws/device path with the misspelled menberId parameter. The RAT maintains a real-time control socket to the operator using this distinctive URI. Detecting it flags a live command-and-control session from an infected device.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.