New Android Malware RemControl Steals Banking PINs

A new Android banking trojan named RemControl targets customers across Europe, Canada, and the Gulf states by disguising itself as a third-party IPTV application called TVTap. Discovered by Group-IB, the malware uses local VPN services to block Google Play Protect, dynamically signs certificates on infected devices, and uses AI-assisted development to steal banking PINs and credentials.

How RemControl Spreads and Bypasses Security

The campaign relies on fake Google Play Store pages that impersonate TVTap, a popular streaming utility absent from the official app marketplace. Group-IB highlights a specific Italian campaign where six distinct websites served the malicious APK exclusively to visitors browsing from Italian IP addresses. These distribution pages incorporate Meta Pixel tracking codes, indicating that the operator actively purchases ads on Meta’s platform to drive traffic.

Upon downloading the dropper, victims face a fake TVTap update screen. Initiating the installation triggers a local VPN service designed to block network traffic originating from the Google Play Store app. This tactic effectively halts real-time security scans by Google Play Protect. The dropper then generates a unique signing certificate directly on the device, signs the malware payload with it, and installs it. This method defeats file hash and certificate-based detection. Group-IB also notes that newer variants employ custom packers to encrypt the malware’s code.

Device Takeover and Credential Theft

Once established on a device, RemControl immediately prompts the user for Android’s Accessibility Service permissions. Group-IB researchers explain that almost every Android banking trojan abuses this exact privilege to gain operational control over the hardware.

With accessibility access granted, RemControl executes a suite of invasive functions:

  • It overlays targeted banking applications with custom phishing screens to capture PINs, mobile banking codes, and card expiry dates, utilizing a target list that operators can modify at any time. Once the victim submits this data, the overlay closes to reveal the authentic banking app underneath.
  • It transmits live screenshots alongside a complete map of text and interface element positions to the attackers.
  • It records every click and typed keystroke across all device applications while permitting remote tapping, swiping, and typing.
  • It captures lock-screen pattern grids, storing sufficient data to reconstruct unlock patterns across ten Android versions, including devices manufactured by Samsung, Xiaomi, and Huawei.
  • It actively locks victims out of crucial settings menus, redirecting them away from screens used to uninstall applications, revoke permissions, or execute factory resets.

Instead of hardcoding a command-and-control server address into the application, RemControl fetches encrypted addresses posted inside two public Telegram channels. This infrastructure allows operators to migrate to new servers without releasing updated APK builds. WebSocket serves as the primary connection protocol, with HTTP functioning as a fallback mechanism.

AI-Assisted Development and Infrastructure

Investigators uncovered publicly accessible documentation for the operator’s server infrastructure, revealing clear fingerprints of artificial intelligence involvement. The documentation classifies the delivery of fake banking login screens and the collection of stolen credentials under benign labels like “quiz answers” and parental monitoring. Researchers noted that

New Android Malware RemControl Steals Banking PINs

What makes this campaign particularly notable is the evidence of AI-assisted development throughout the infrastructure. The operator appears to have used an AI assistant to build significant portions of the C2 backend and phishing overlays under the guise of a parental monitoring application, with the AI unaware of what it was actually building,

as explained by Group-IB. Further supporting this finding, a complete AI assistant response was discovered accidentally left inside the HTML of one phishing page, and API documentation explicitly referred to credential submissions as quiz answers.

These components demonstrate that RemControl operates as a Malware-as-a-Service model. The exposed API panel allowed operators to manage infected devices, modify overlays, record remote sessions, and generate new APK builds equipped with individual affiliate tags.

Attribution and Affected Institutions

The malware impacts customers of more than 30 financial institutions located across Italy, France, Spain, Poland, Portugal, Canada, and select Gulf states. VirusTotal first received sample submissions of the trojan on July 19, 2026, following the registration of its C2 domain two months earlier on May 12, 2026.

ToxicPanda 2.0 Steals Banking PINs! Claude AI Hack, OpenAI & WatchGuard Alert

Group-IB tracks the mastermind behind these campaigns under the tag UNKK, derived from an affiliate identifier embedded within every analyzed sample. Researchers have pointed out potential operational overlaps with UNKN, an affiliate group associated with the Medusa banking trojan. Both entities rely on identical dropper naming conventions, share similar distribution methods, and utilize Telegram channels to obscure their backend servers, while their respective affiliate tags differ by only a single letter.

Despite these overlapping indicators, investigators maintain caution. Group-IB concluded that

While these indicators are suggestive of a common operator, a definitive link cannot be established from available evidence.

Comments written in Russian within several fake login screen files indicate that at least a portion of the source code was authored by a Russian speaker.

Android's Manic Malware Steals Your PIN and Going Offline Won't Help

Related reading


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.