New Android Banking Trojan Uses AI-Built Overlays to Steal Users’ Banking PINs
RemControl, a new Android banking trojan, uses fake streaming-app downloads and overlays to steal banking PINs.
Group-IB identified RemControl, an Android banking trojan first seen in July 2026, delivered through fake Google Play-style pages for a TV streaming app and geo-filtered in at least one Italian campaign. When a targeted banking app opens, it shows a full-screen overlay that captures PINs, codes, and card details, then hides; operators can log keystrokes, stream screenshots, and control the device after Accessibility access is granted. Matching overlays cover more than 30 banks across Europe, the Middle East, and Canada, with Italy and France the main observed targets. Server notes and a leftover AI-assistant reply indicate an AI tool helped build parts of the platform, while C2 locations are retrieved through Telegram under an affiliate label UNKK.
- Group-IB traced RemControl samples first seen in July 2026, mainly in Italy and France.
- Overlays match more than 30 banks in Europe, the Middle East, and Canada.
- It abuses VPN and Accessibility access to capture input and control the phone.
- Operators rotate C2 via Telegram and use a fresh signing certificate per install.
- AI helped build phishing pages; the trojan does not run AI on the device.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bnbnhura.top | //telegram[.]me/+Psyt04xu-cRjMTg0 Telegram dead-drop Domain bnbnhura[.]top RemControl proxy server URL hxxps[:]//definatelynoone[.]c |
| domain | cdn.dlmafi.top | ]askarzadeh[.]com/ Fake TVTap download website URL hxxp[:]//cdn[.]dlmafi[.]top/ Fake TVTap download website URL hxxp[:]//216[.]126[.]2 |
| domain | definatelynoone.com | Domain bnbnhura[.]top RemControl proxy server URL hxxps[:]//definatelynoone[.]com Operator panel URL hxxps[:]//157[.]90[.]179[.]116 Operato |
| domain | ff-de.shutgpt.ir | .]doneplay[.]site/ Fake TVTap download website URL hxxp[:]//ff-de[.]shutgpt[.]ir/ Fake TVTap download website URL hxxp[:]//vpn[.]askarza |
| domain | telegram.me | tvtap-liveapp[.]com/dl.php Final download URL URL hxxps[:]//telegram[.]me/ftestera Telegram dead-drop URL hxxps[:]//telegram[.]me/+ |
| domain | tvtap-hd.app | ompromise (IoCs):- Type Indicator Description URL hxxps[:]//tvtap-hd[.]app/ Fake TVTap download website URL hxxp[:]//vpn[.]doneplay[ |
Full article949 words · extracted from cybersecuritynews.com · click to collapse
A new Android banking trojan is turning an app download into a banking PIN trap. Called RemControl, it hides behind fake download pages for a television streaming app, then waits for banking apps to open.
The campaign uses pages that look like Google Play listings, even though the streaming app is not offered there.
In one Italian campaign, the pages delivered the malicious installer only to Android visitors with Italian IP addresses, hiding the trap from others. Researchers from Group-IB identified RemControl and traced its activity to samples first seen in July 2026.
Group-IB said in a report shared with Cyber Security News (CSN) that more than 30 banking institutions across Europe, the Middle East and Canada have matching phishing screens.
%20(Source%20-%20Group-IB).webp)
No victim count is confirmed; while the Italy and France were the main targets observed. The discovery adds to concerns about fake streaming app downloads used to place powerful malware on phones.
RemControl goes further than stealing a login: it can watch the screen, record input and let an operator control an infected device remotely.
New Android Banking Trojan Uses AI-Built Overlays
When a targeted banking app opens, RemControl places a full-screen copy of a bank interface over it. The victim may type a PIN, mobile banking code or card expiry date into the imitation. Once the details are submitted, the fake screen closes and the genuine app reappears.
The fake pages arrive from an attacker-controlled server rather than being stored in the installed app. That lets operators change targets without asking victims to install another file. It resembles the technique used by other Android banking trojans that position false screens over trusted apps.
.webp)
The unusual detail is AI-assisted development. Investigators found server documentation describing stolen banking details as quiz answers and remote access as parental monitoring. A complete AI assistant reply, including notes and an offer to make more, had been left inside a live phishing page.
Those clues suggest an AI assistant helped build parts of the criminal platform under a misleading description of its purpose. That does not mean the malware uses AI on the phone. The immediate danger is still the convincing screen that asks for sensitive details at the wrong moment.
Installation and Remote Control
The installer first shows a false streaming app update screen. It then asks for VPN permission and uses a local connection to cut off network traffic from the Play Store during installation, interfering with real-time security checks.
Each installation receives a newly generated signing certificate, complicating detection based on previously seen files. After installation, the trojan asks for Android Accessibility access.
It lets malware read the screen, capture screenshots and make taps or swipes for the operator. Similar permission abuse is described in reporting on Perseus banking malware campaigns that also used fake streaming apps.
RemControl can log typed text and inspect a device’s on-screen controls while streaming screenshots. It can also gather information needed to reconstruct an unlock pattern and push users out of settings screens when they try to remove it. These features make the risk broader than a single stolen banking PIN.
.webp)
The operation resembles a service for other criminals. An exposed control panel offered tools for creating app builds, managing infected devices and viewing captured credentials.
Investigators linked the observed samples to an affiliate label, UNKK, but described a possible connection to another banking malware network as unproven.
The malware fetches its server location through Telegram, allowing operators to change where infected phones connect without rebuilding the app.
Updated overlays help the campaign shift targets. It follows a wider pattern of banking PIN theft attempts that combine deceptive screens with remote phone control.
Users should avoid app downloads offered through links or unfamiliar websites, even when a page resembles an official store.
Review unexpected VPN and Accessibility requests, and never enter banking details into a screen that appears without warning. Anyone who suspects account misuse should contact their bank through official channels.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[:]//tvtap-hd[.]app/ | Fake TVTap download website |
| URL | hxxp[:]//vpn[.]doneplay[.]site/ | Fake TVTap download website |
| URL | hxxp[:]//ff-de[.]shutgpt[.]ir/ | Fake TVTap download website |
| URL | hxxp[:]//vpn[.]askarzadeh[.]com/ | Fake TVTap download website |
| URL | hxxp[:]//cdn[.]dlmafi[.]top/ | Fake TVTap download website |
| URL | hxxp[:]//216[.]126[.]229[.]216/ | Fake TVTap download website |
| URL | hxxps[:]//tvtap-liveapp[.]com/dl.php | Final download URL |
| URL | hxxps[:]//telegram[.]me/ftestera | Telegram dead-drop |
| URL | hxxps[:]//telegram[.]me/+Psyt04xu-cRjMTg0 | Telegram dead-drop |
| Domain | bnbnhura[.]top | RemControl proxy server |
| URL | hxxps[:]//definatelynoone[.]com | Operator panel |
| URL | hxxps[:]//157[.]90[.]179[.]116 | Operator panel |
| Tracking ID | 997470916598588 | Meta Pixel ID embedded in distribution pages |
| Tracking ID | 1909605966397328 | Meta Pixel ID embedded in distribution pages |
| File name pattern | instal*tvtap*.apk | Dropper naming convention noted in the investigation |
| Configuration marker | numeraZZZas | Marker used to decode the server address |
| SHA-256 | 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b | Dropper |
| SHA-256 | fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e | Dropper |
| SHA-256 | 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 | Dropper |
| SHA-256 | dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 | Dropper |
| SHA-256 | 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb | Dropper |
| SHA-256 | 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 | Dropper |
| SHA-256 | 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d | Dropper |
| SHA-256 | cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 | Dropper |
| SHA-256 | 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 | Dropper |
| SHA-256 | af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c | Payload |
| SHA-256 | 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c | Payload |
| SHA-256 | c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 | Payload |
| SHA-256 | 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f | Payload |
| SHA-256 | 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a | Payload |
| SHA-256 | ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f | Payload |
| SHA-256 | b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 | Payload |
| SHA-256 | 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 | Payload |
| SHA-256 | 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 | Payload |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.