HomeCyber BalkansRemControl Android Malware Targets Over 30 Banking Apps to Steal PINs and...

RemControl Android Malware Targets Over 30 Banking Apps to Steal PINs and Credentials

Published on

spot_img

Newly Discovered Android Banking Trojan Targeting Financial Institutions

A recently discovered Android banking trojan, named RemControl, poses a significant threat to customers of over 30 financial institutions throughout Europe, the Middle East, and Canada. This sophisticated malware employs a combination of deceptive tactics to compromise mobile banking sessions, leveraging fake Google Play pages, abusing Android’s Accessibility Service, and implementing credential-stealing overlays alongside real-time screen streaming and remote-control functionalities.

The cybercrime operation behind RemControl has been identified as UNKK, a designation attributed to the detection of hardcoded affiliate and campaign identifiers gleaned from analyzed malware samples. Initial campaigns associated with this malware have been traced back to as early as May 2026, with the first samples appearing in July of the same year.

The attack campaign begins with the creation of counterfeit Google Play Store pages that masquerade as legitimate applications, specifically targeting TVTap, a third-party IPTV app frequently sought after from unofficial download sites. These malicious pages are crafted to look authentic and, in at least one case targeting Italy, were able to verify visitors’ IP geolocation and mobile User-Agent prior to delivering the malicious APK file.

In a critical turn of events, researchers discovered that Meta Pixel tracking IDs were embedded within these fraudulent pages. This suggests that malvertising may have played a pivotal role in directing unsuspecting users to download these harmful applications. Once the application is installed, the RemControl dropper presents a deceptive WebView-based interface, posing as an update prompt for TVTap.

One of the key features of the malware is its ability to exploit Android’s VPN functionality to obstruct network traffic associated with the Google Play Store package, specifically com.android.vending, thereby hampering the connectivity required for Google Play Protect during the installation process. This maneuver is particularly alarming as it limits real-time scanning during a critical phase of the attack.

Furthermore, the dropper generates a unique signing certificate for each installation attempt utilizing Android Keystore functionality. As a result, each payload carries a distinct certificate and hash, making traditional hash- and certificate-based detection methods ineffective.

Recent variants of the malware have introduced a custom DEX packer that secures its code. The decryption key for this packed code is derived from the APK signing certificate, amplifying the complexity in detecting malicious activities tied to individual builds. Once the victim unknowingly grants Accessibility Service permissions, RemControl gains the necessary capabilities to hijack banking operations.

According to researchers from Group-IB, RemControl operates as a Malware-as-a-Service platform and has shown sustained activity, particularly with overlays targeting banking applications in various countries including Italy, France, Spain, Poland, Portugal, Canada, as well as member states of the Gulf Cooperation Council. Notably, Italy and France have been flagged as major initial targets.

The malware’s stealth extends to monitoring foreground applications while dynamically fetching a target list from its command-and-control (C2) server. Strings within both the dropper and payload are obfuscated using Base64 encoding and XOR decryption against a hardcoded key, masking crucial information from simple inspections.

When a targeted banking application launches, RemControl overlays its legitimate interface with a full-screen WebView, effectively capturing critical data such as Personal Identification Numbers (PINs), banking codes, card expiration dates, and other sensitive login information. The content for these overlays is not hardcoded; rather, it is dynamically pulled from the C2 server, allowing operators to alter phishing templates or retarget infected devices effortlessly.

The expansive reach of RemControl also allows it to capture device screenshots and transmit them in real time using various encoding methods, providing operators with not only visual access but a structured, machine-readable representation of the victim’s device. This extensive data collection includes logging user interactions across applications, thereby enhancing the trojan’s capability to manipulate user behavior surreptitiously.

In a noteworthy operational oversight, the campaign has been linked to the accidental inclusion of an AI-generated response appended to a live banking-phishing overlay, highlighting the evolving nature of cybersecurity threats.

For enhanced resilience, the malware utilizes Telegram as a dead-drop resolver. The infrastructure behind RemControl is robust enough to allow operators to rotate elements without recompiling the malware. Group-IB also reported on publicly available API documentation for infrastructure associated with “RemControl Proxy” and its operator panel, which revealed capabilities for managing bots, editing overlays, viewing credential results, and more.

Given the intricate nature of RemControl and its deployment as a Malware-as-a-Service operation, cybersecurity experts stress the crucial need for immediate attention in order to mitigate potential damages. This sophisticated malware sets a new precedent in the realm of cyber threats, blending advanced programming techniques with deceptive tactics to facilitate one of the most extensive banking fraud campaigns observed to date.

In summary, the emergence of RemControl underlines the urgent necessity for enhanced security measures among financial institutions and mobile banking users alike, emphasizing the importance of vigilance against such advanced cyber threats.

Source link

Latest articles

Okta Establishes Identity as the Control Plane for AI Agents

Okta Expands AI Agent Identity Management Amid Growing Cybersecurity Challenges In a significant move within...

Why Cyera’s Latest Funding Round Sparks IPO or Sale Debate

Cyera's Meteoric Rise: Navigating the Future of Data Security In the fast-evolving landscape of cybersecurity,...

Ransomware, AI, and New Priorities for Manufacturing Cyber Resilience Webinar

Ransomware Threats: Navigating the Landscape of AI and Cyber Resilience in Manufacturing In a recent...

EU KIDS Act Establishes New Age Limits for Social Media Usage

European Commission Proposes Stricter Age Restrictions on Social Media Access for Children through KIDS...

More like this

Okta Establishes Identity as the Control Plane for AI Agents

Okta Expands AI Agent Identity Management Amid Growing Cybersecurity Challenges In a significant move within...

Why Cyera’s Latest Funding Round Sparks IPO or Sale Debate

Cyera's Meteoric Rise: Navigating the Future of Data Security In the fast-evolving landscape of cybersecurity,...

Ransomware, AI, and New Priorities for Manufacturing Cyber Resilience Webinar

Ransomware Threats: Navigating the Landscape of AI and Cyber Resilience in Manufacturing In a recent...