Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » New RemControl Android Banking Malware Targets Users Across Europe, Canada, and the Middle East

New RemControl Android Banking Malware Targets Users Across Europe, Canada, and the Middle East

By:
Last updated:September 24, 2026
Human Written
  • A new Android malware called RemControl targets banking customers in Europe, Canada, and the Middle East.

  • Criminals spread it through fake Google Play pages that copy the TVTap IPTV app.

  • Researchers say it blocks Google’s safety checks and lets the operator control infected phones remotely.

New RemControl Android Malware Targets Banking Customers Across Three Regions

Cybersecurity company Group-IB has uncovered a new Android malware platform called RemControl. It follows the malware-as-a-service (MaaS) model, so it works as a ready-made tool for online criminals. Its goal is to steal banking credentials from phone users.

Attackers spread it through malvertising campaigns, which are harmful online ads. These ads impersonate the TVTap IPTV app, according to BleepingComputer. IPTV apps stream TV channels over the internet. According to Group-IB researchers, the malware targets users in Europe, Canada, and the Middle East. The European list includes Italy, France, Spain, Poland, and Portugal.

Fake Google Play Pages Lure Victims to Harmful Downloads

The trap begins with a page that looks like Google Play. RemControl spreads through fake Google Play pages that impersonate the TVTap IPTV app. A victim who taps download gets a setup file that carries the malware.

The operators built their system before the first attack samples surfaced. Group-IB says the infrastructure has been active since at least May. Researchers first observed samples in July. Those samples contained more than 30 phishing overlays, which are fake screens made to steal banking credentials.

At least one Italian campaign used extra checks before showing the page. It used geofencing, which limits a page to visitors in chosen places. It also checked for a mobile User-Agent, which confirms the visitor browses from a phone.

The fake sites also include Meta Pixel tracking IDs. Group-IB sees this as a hint that the operator abused Meta’s advertising ecosystem. The researchers suspect those ads drove victims to the download pages.

Ransomware operators also use gaming-related businesses as targets. PLAY ransomware claims breach of US gaming company J&J gaming covers an alleged attack on a U.S. gaming company.

The next trick is the most important one. When launched, the setup file starts a VPN service on the phone. This VPN blocks traffic from Google Play services. As a result, Play Protect cannot run real-time checks against known malware. Play Protect is Google’s built-in guard for apps. The VPN stops that guard from doing its job.

Group-IB also saw this feature in a recent version of ToxicPanda. That malware runs a much bigger operation. It uses fake screens for 349 banking, financial, cryptocurrency, and e-wallet apps. Those apps serve users in 16 countries.

One Permission Request Hands RemControl Control of the Phone

During installation, the malware asks for Accessibility Service permissions. Android designed this feature to help with accessibility needs. If the victim approves the request, RemControl can perform several harmful actions, BleepingComputer reported.

The first action targets banking apps. RemControl shows a full-screen fake page on top of a real banking app. Victims who type into it hand over PINs, banking codes, card expiry dates, and credentials. The malware also receives new banking targets from the command-and-control (C2) infrastructure. That is the system that sends orders to the malware.

The second group of actions lets the operator watch the phone. RemControl streams screenshots and the full layout of the Android screen (the accessibility tree) to the operator in real time. It also records clicks, text changes, focus events, and other input across apps. It works like someone looking over the owner’s shoulder.

The third group of actions lets the operator take charge. The malware can remotely perform taps, swipes, scrolling, gestures, and long presses. It can also inject text. In simple terms, the operator can touch and type from far away. RemControl can capture the coordinates of the lock pattern people draw to open a phone. This works on Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android devices.

RemControl also fights removal. It detects when victims enter settings for app management, accessibility, or factory reset. Then it exits automatically, which prevents removal.

The malware keeps its control servers flexible. It retrieves encrypted C2 information from Telegram channels, a messaging platform. This lets it rotate infrastructure dynamically in case of disruptions. In plain words, it can move to new servers when old ones stop working.

Researchers Track the Operator and Share Safety Tips

Group-IB found a slip in the attackers’ setup. FastAPI documentation was exposed in the initial C2 proxy. This public guide revealed the web addresses the malware used. The malware used them to fetch banking overlays and submit stolen credentials. In simple terms, the operator left a guide to the system where researchers could read it.

The research also points to help from artificial intelligence. In one overlay, the malware displays an AI assistant response. BleepingComputer calls this a strong indication that AI models helped build it. The attacker’s origin remains unclear. However, the researchers found Russian language in the code of some overlay pages. That indicates a Russian speaker developed at least some of them.

Group-IB tracks the operator as UNKK. The researchers based this on a common identifier in the analyzed samples. They also suspect a connection to the Medusa banking trojan. Medusa is malware built to steal bank details.

The report also advises Android users to avoid APK files from outside Google Play. APK files are the installer files for Android apps. The only exception is a publisher they explicitly trust. Regular Play Protect scans are another recommended habit. Users should also decline Accessibility Service requests from apps that do not need them for accessibility purposes.

These habits match the tricks RemControl uses, from fake download pages to unnecessary permission requests.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.