RemControl Android banking trojan steals PINs from customers of 30+ banks in Europe, Canada, and the Middle East
Group-IB tracks RemControl, a new Android banking malware-as-a-service delivered via fake TVTap IPTV Google Play pages and malvertising, using Accessibility abuse to overlay 30+ banking apps, steal PINs and card data, and give operators real-time remote…
All six reports cite Group-IB research on RemControl, an Android banking trojan sold as malware-as-a-service. Timing is disputed: GBHackers says it has been active since at least May 2026, Help Net Security reports the first VirusTotal samples were submitted on July 19, 2026, and Cyber Security News and Infosecurity Magazine date first sightings and targeting from July 2026. Distribution runs through malvertising and fake Google Play pages impersonating the TVTap IPTV app, with geolocation and User-Agent checks; Help Net Security describes an Italian campaign restricted to Italian IP addresses and promoted with Meta ads. After the victim grants VPN and Accessibility Service permissions, the dropper suppresses Google Play Protect by starting a VPN service — Infosecurity Magazine describes this as routing Play Protect through a null VPN — signs each payload with a unique per-install certificate, and, per GBHackers' brief, uses custom crypto. The malware then displays full-screen phishing overlays over banking apps to steal PINs, credentials, and card data including card expiry dates, while also keylogging, stealing pattern locks, streaming screenshots and the Android accessibility tree to operators over WebSocket, injecting remote taps, and blocking uninstallation. Command-and-control configuration is fetched from public Telegram channels acting as a dead-drop resolver for rotating WebSocket C2 addresses; BleepingComputer reports that exposed FastAPI documentation revealed overlay-delivery and credential-submission endpoints. Matching overlays cover customers of more than 30 banks — Help Net Security lists Italy, France, Spain, Poland, Portugal, Canada, and some Gulf states, Cyber Security News says Italy and France are the main observed targets, and Infosecurity Magazine summarizes the scope as six countries, a discrepancy the outlets do not resolve. Group-IB tracks the operator as UNKK, describes it as Russian-speaking, and cites a possible but unconfirmed link to the Medusa banking trojan affiliate ecosystem (Help Net Security names affiliate UNKN). A leftover AI-assistant reply and backend documentation indicate AI assistance in building the overlays and C2 backend; Cyber Security News notes the trojan itself does not run AI on the device.
- RemControl is a new Android banking trojan sold as malware-as-a-service; all six reports attribute the research to Group-IB.
- Targets customers of more than 30 banks; Help Net Security lists Italy, France, Spain, Poland, Portugal, Canada, and Gulf states, Cyber Security News says Italy and France are the main observed targets, and Infosecurity Magazine summarizes…
- First sightings disputed: active since at least May 2026 (GBHackers); first VirusTotal sample submitted July 19, 2026 (Help Net Security); first seen July 2026 (Cyber Security News, Infosecurity Magazine).
- Delivery via malvertising and fake Google Play pages impersonating the TVTap IPTV app, with geolocation and User-Agent checks; an Italian campaign was limited to Italian IP addresses and promoted with Meta ads (Help Net Security).
- Dropper blocks Google Play Protect by starting a VPN service (Infosecurity Magazine: routing Play Protect through a null VPN) and signs each payload with a unique certificate; GBHackers' brief also cites custom crypto.
- Accessibility Service abuse enables full-screen banking overlays, keylogging, pattern-lock theft, streaming of screenshots and the accessibility tree over WebSocket, remote taps, and blocking of uninstallation.
- C2 addresses are rotated via public Telegram channels acting as a dead-drop resolver; BleepingComputer reports exposed FastAPI documentation revealed overlay and credential endpoints.
- Operator tracked as UNKK, described as Russian-speaking, with a possible but unconfirmed link to the Medusa banking trojan and its affiliate UNKN (Help Net Security).
Coverage timelineoldest first · each row is one article
- · 3d agoNew RemControl Android banking malware targets users in Europe and Canada
BleepingComputer· 58
New RemControl Android banking MaaS steals credentials via 30+ phishing overlays targeting Europe, Canada, and the Middle East.
- · 3d agoRemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
GBHackers· 76
RemControl Android trojan overlays 30-plus banking apps, stealing PINs and streaming screens through accessibility abuse.
- · 2d agoNew Android malware RemControl steals banking PINs and blocks removal attempts
Help Net Security· 73