ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
ThreatsDay details the RemControl Android banking trojan, a ZCode source leak, and related phishing and ICS risks.
Group-IB described RemControl, an Android banking trojan first seen in July 2026, targeting retail customers in Italy, France, Spain, Poland, Portugal, the Middle East, and Canada through fake TVTap Google Play pages promoted in Meta ads. It abuses Accessibility Service for phishing overlays, live screen streaming, keylogging, and remote control, and resolves command-and-control through an encrypted Telegram dead-drop; Russian-language comments and a possible link to the Medusa UNKN affiliate botnet were noted. Separately, Z.ai disabled ZCode features that uploaded local code repositories to Alibaba Cloud by default, and FBI and CISA warned critical-infrastructure operators about broad access for third-party ICS integrators. The bulletin also describes surveillance features in Russia's MAX super-app and a fake Claude Max giveaway that steals Google credentials with a browser-in-the-browser login.