Rising Threat: New Android Banking Trojan Named RemControl
Recent findings from cybersecurity experts at Group-IB have unveiled a newly-discovered Android banking trojan that poses a significant threat to financial security. This trojan, dubbed RemControl by its operator, exploits Accessibility Services to gain unauthorized remote control over victims’ devices, enabling it to siphon sensitive credentials such as PIN codes, mobile banking codes, and card expiry dates.
Targeting Multiple Regions
Since July 2026, RemControl has been actively targeting retail banking customers across Western Europe, the Middle East, and Canada. With confirmed attacks on over thirty banking institutions across six countries, Group-IB researchers have categorized this trojan as a grave threat to both banking entities and their customers. The malware is engineered to support multiple languages, which raises concerns that its operators may extend their reach to additional regions in the near future.
AI Assistance in Malware Development
The developers behind RemControl are believed to be part of a Russian-speaking group known as UNKK. They have reportedly manipulated an AI assistant to create substantial parts of the command and control (C2) backend and the phishing overlays utilized in the trojan’s operation. Initially, the developer appears to have misled the AI model into thinking that the generated API endpoints were meant for a legitimate parental monitoring application. The end result has been a functional banking fraud platform that bizarrely describes credential theft as "quiz completion" with banking victims referred to as “a person staring at the quiz.” This unusual terminology highlights the disturbing creativity employed in the development of the trojan.
During their analysis, researchers stumbled upon exposed API documentation from RemControl’s C2 panel. This accidental discovery provided them with a deeper understanding of the underlying infrastructure supporting this malicious software.
Mechanisms of Control
Victims find themselves ensnared by RemControl through deceptive Google Play Store pages that masquerade as the popular TVTap IPTV application. These fraudulent pages are tailored to local languages based on the user’s location, increasing their effectiveness. Upon downloading the application, unsuspecting victims are presented with a user interface that mimics a TVTap update screen. If a victim clicks “install,” a dropper is activated that implements various measures to evade detection while installing the RemControl malware.
One of the tactics employed by the malware includes launching a local VPN service that reroutes traffic from Google Play Protect, a built-in malware defense tool for Android, through a null VPN channel. This VPN-based suppression of Play Protect is becoming an increasingly common strategy in the arsenal of Android malware developers, demonstrating a heightened awareness of mobile security mechanisms.
Furthermore, the dropper generates a fresh signing key using the Android Keystore, allowing it to sign the RemControl payload prior to installation in order to evade hash-based detection techniques.
Once the malware is installed, it promptly requests Accessibility Service permissions from the victim. If granted, this access allows RemControl to take full control over the victim’s device. The Android Accessibility Service is primarily designed to aid individuals with disabilities in navigating their devices, but in this case, it is exploited for nefarious purposes.
Data Collection Methods
With control established, RemControl is able to execute various functions aimed at capturing sensitive banking information. One of its methods involves displaying a full-screen WebView overlay that collects crucial credentials like PIN codes, mobile banking codes, and card expiry dates, depending on the bank being targeted. This overlay completely obscures the legitimate banking application from the victim’s view.
Additionally, the trojan takes advantage of the Accessibility Service to capture the device’s screen, thus providing the operator with a machine-readable map of all visible UI elements, including their respective coordinates, text content, and interactive state. This enables the attacker to monitor user activity through keylogging and pattern locks, tracking clicks, selection changes, and unlock patterns.
Maintaining persistent access to the victim’s device is also a priority for RemControl, which has self-preservation functions to obstruct application removal and factory reset options.
To further conceal its activities, captured data is transmitted using a Telegram dead-drop mechanism, which obscures the actual C2 address behind an additional layer of secrecy. The primary communication channel operates on WebSocket, employing a JSON envelope that contains multiple fields, including command identifiers and data payloads.
Warning for Banking Customers
In light of the rising threat posed by RemControl, Group-IB has issued specific recommendations for Android users to help protect themselves:
- Avoid clicking on suspicious links received through various channels, including email, SMS, or social media.
- Only download applications from reputable sources such as the Google Play Store.
- Be wary of applications requesting excessive or unexpected permissions, especially concerning Accessibility Services.
- Never enter banking information on screens that appeared unexpectedly.
As cyber threats evolve, the importance of vigilance cannot be overstated. With operations like RemControl gaining ground, those utilizing mobile banking services must remain informed and cautious to safeguard their financial information.
