RemControl Android banking malware hits Europe and Canada
A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.
Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.
Fake Google Play pages and ad-driven traffic
Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.
The fake sites also carry Meta Pixel tracking IDs. Group-IB reads this as a sign that the operator used Meta's advertising ecosystem to push traffic toward the download pages.
One detail stands out. In one of the overlays, the malware shows what appears to be a response from an AI assistant. Researchers take this as a strong hint that AI models helped build it.
Blinding Play Protect with a VPN
Once launched, the dropper starts a VPN service that blocks traffic from Google Play services. This stops Play Protect, Google's built-in malware scanner, from running real-time checks against known threats.
The trick is not unique to RemControl. A recent version of ToxicPanda, a much larger banking malware operation with phishing overlays for 349 banking, financial, cryptocurrency and e-wallet apps across 16 countries, uses the same approach.
What Accessibility access unlocks
During installation, RemControl asks for Accessibility Service permissions. Android offers these to help users with disabilities, but they give an app broad control over the device. If the victim grants them, the malware can:
- show full-screen phishing overlays on top of real banking apps to steal PINs, banking codes, card expiry dates and login credentials
- pull new banking targets from its command-and-control (C2) servers on the fly
- stream screenshots and the full accessibility/UI tree to the operator in real time
- log clicks, text changes, focus events and other input across apps
- carry out taps, swipes, scrolling, gestures, long presses and text injection remotely
- capture pattern-lock coordinates on devices from Samsung, Xiaomi, Huawei, OPPO, OnePlus and on stock Android
- block removal by spotting when the victim opens app management, accessibility or factory-reset settings and immediately backing out of them
To stay resilient, RemControl fetches encrypted C2 details from Telegram channels. This lets the operator swap infrastructure quickly if servers are taken down.
Group-IB also found exposed FastAPI documentation on the initial C2 proxy. It revealed the endpoints the malware used to download banking overlays and upload stolen credentials.
Who is behind it
The operator's origin is unclear. Russian-language text in the HTML of some overlays suggests that a Russian speaker built at least part of them. Based on a shared identifier found across the samples, Group-IB tracks the operator as UNKK and suspects a link to the Medusa banking trojan.
Users are advised not to install APK files from outside Google Play unless they fully trust the publisher. Running Play Protect scans regularly and rejecting Accessibility requests from apps that have no genuine accessibility purpose are also recommended.
Our Take
RemControl follows a familiar formula, but it shows how cheaply that formula can now be packaged and sold. A MaaS model means the people running campaigns do not need to write the malware themselves, and the AI assistant text left in an overlay suggests the developers are also using AI to speed up their own work.
The VPN trick against Play Protect is the part defenders should watch most closely. It first showed up in ToxicPanda and now appears in a separate family, which suggests it may be turning into a standard feature. If so, users who rely only on Google's built-in protection may be less safe than they think.
The distribution side matters too. Pirated or grey-market streaming apps make an easy lure, and paid ads give attackers reach. Malware authors keep finding new delivery tricks on every platform, as recent MacSync activity on macOS shows. It is worth watching whether ad platforms tighten checks on campaigns that point to fake app store pages, and whether the suspected Medusa connection holds up as more samples surface.
Sponsored Recommended for you – discover more →
