Back to Feed
MalwareSep 23, 2026

New RemControl Android banking malware targets users in Europe and Canada

New RemControl Android banking malware targets users in Europe and Canada via malvertising.

Summary

A new Android malware-as-a-service (MaaS) platform named RemControl is actively targeting users in Europe and Canada through malvertising campaigns. It impersonates legitimate applications like TVTap IPTV and uses sophisticated techniques, including blocking Play Protect and requesting Accessibility Service permissions, to steal banking credentials and sensitive data. The malware also exhibits AI-assisted features and retrieves command-and-control information from Telegram channels.

Full text

New RemControl Android banking malware targets users in Europe and Canada By Bill Toulas September 23, 2026 05:25 PM 0 A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials. Researchers at cybersecurity company Group-IB say that the malware targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East. In one of the overlays, the malware displays an AI assistant response, a strong indication that it has been built with the help of AI models. Phishing overlay exposing the use of AISource: Group-IB RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks. The malicious sites include Meta Pixel tracking IDs, which Group-IB sees as a hint that the operator abused Meta’s advertising ecosystem to drive victims to the download pages. Fake Google Play siteSource: Group-IB When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks against known malware. The feature has also been observed in a recent version of the ToxicPanda malware, a much bigger operation that uses phishing overlays for 349 financial, cryptocurrency, and digital wallets applications used in 16 countries. phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries. During installation, the malware requests approval for Accessibility Service permissions. Source: Group-IB If the requested permissions are granted, RemControl can perform the following actions: Display full-screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials Dynamically receive new banking targets from the command-and-control (C2) infrastructure Stream screenshots and the full Android accessibility/UI tree to the operator in real time Record clicks, text changes, focus events, and other user input across applications Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection Capture Android pattern-lock coordinates across several OEMs, including Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android Prevent removal by detecting when victims enter application-management, accessibility, or factory-reset settings and automatically exiting RemControl retrieves encrypted C2 information from Telegram channels, so it can rotate infrastructure dynamically in case of disruptions. Group-IB found FastAPI documentation exposed in the initial C2 proxy that revealed the endpoints the malware used to fetch banking overlays and to submit stolen credentials. The origin of the threat actor behind RemControl is unclear, but the researchers found Russian language in the HTML files of some overlays, indicating a Russian speaker as the developer of at least some of them . Based on a common identifier in the analyzed samples, the researchers track the RemControl operator as UNKK and suspect a connection to the Medusa banking trojan. Android users are advised to avoid downloading APK files from outside Google Play unless they explicitly trust the publisher. Regular Play Protect scans and declining Accessibility Service permission requests from apps that do not require them for accessibility purposes are also recommended security practices. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: New RatHat Android malware uses AI to automate device controlToxicPanda Android malware uses VPN permissions to block Google PlayNew Manic Android malware can exfiltrate data through nearby devicesAnthropic warns infostealer malware is hijacking Claude sessions to drain usageNew ClosedQuorum Windows malware uses AI for attack decisions

Indicators of Compromise

  • malware — RemControl
  • malware — UNKK
  • malware — Medusa

Entities

TVTap IPTV (product)malware-as-a-service (technology)AI (technology)FastAPI (technology)Meta Pixel (technology)Play Protect (product)