Oblivion is an Android remote access trojan sold as a commercial subscription malware offering. It has been marketed as an easy-to-operate tool intended to lower the barrier to entry for cybercriminals and stalkerware-style operators, with public advertising and builder functionality for generating trojanized Android applications. Reporting has also linked RedWing to the Oblivion family as a likely newer variant based on similarities in droppers and overlay mechanisms, although that relationship has not been conclusively confirmed.
Oblivion targets Android devices and relies on social engineering rather than a disclosed Android exploit. A commonly reported infection lure is a fake Google Play update prompt or similarly disguised fake application/update flow. After execution, the malware abuses Android Accessibility Service to obtain broad control over the device and silently grant itself extensive permissions. Documented capabilities include theft of SMS messages, including banking authentication codes, keylogging to capture passwords and PINs, and covert remote access features such as live screen viewing and hidden interaction with the device while displaying deceptive update-themed screens to the victim. It has also been reported to support remote unlocking after device restart.
Oblivion has been described as designed for scale, with backend infrastructure reportedly capable of handling large numbers of concurrent victims, and with operator anonymity features such as Tor access. It has been advertised as compatible across a wide range of Android versions and as able to bypass or work around OEM security layers on major Android distributions. The malware is notable for combining commodity MaaS-style packaging, accessibility abuse, credential and SMS theft, and remote-control functionality into a broadly accessible Android RAT offering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier suspected related Android rent-a-malware kit that RedWing may be a variant of, based on shared droppers and overlays.
Referenced as the likely predecessor or closely related malware family to RedWing, based on similarities in the dropper and overlay mechanisms.
Referenced as the Android malware family that RedWing appears to be a variant of.
Referenced as the apparent malware family root or lineage for RedWing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.