RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
RemControl, an Android banking trojan, remotely controls devices and steals credentials from customers of 30-plus banks.
Group-IB describes RemControl, an Android banking trojan that abuses Accessibility Services to remotely control devices and steal PINs, mobile-banking codes, and card expiry dates. It has targeted customers of more than 30 banks across six countries in Western Europe, the Middle East, and Canada since July 2026. Victims are lured by fake Google Play pages impersonating TVTap; a dropper routes Play Protect through a null VPN, signs the payload with a fresh key, and requests Accessibility access for overlays, screen capture, keylogging, and resistance to removal. Operator UNKK, described as Russian-speaking, appears to have used an AI assistant to build portions of the C2 backend and phishing overlays, and stolen data is relayed through a Telegram dead-drop and WebSocket channel.