A new Android banking trojan called RemControl is using fake streaming-app downloads to turn infected phones into credential-stealing remote access devices. When a targeted banking application opens, the malware displays a convincing full-screen imitation and captures information such as a banking PIN, mobile access code or card expiration date.
Group-IB researchers traced samples to July 2026 and identified matching phishing overlays for more than 30 financial institutions across Europe, the Middle East and Canada. Italy and France were the main observed targets, but no confirmed victim count has been released. The operation combines familiar overlay fraud with surveillance and interactive control capabilities that can support theft beyond a single login.
Fake store pages deliver the malicious installer
The campaign promotes a television-streaming application through pages designed to resemble Google Play, even though the app is not offered in the official store. In one Italian distribution chain, the site delivered the malicious package only to Android visitors using Italian IP addresses. Selective delivery helps conceal the payload from researchers, automated scanners and visitors outside the intended region.
After launch, the installer displays a fabricated update screen. It requests VPN permission and establishes a local connection that disrupts Play Store traffic during installation, interfering with real-time security checks. Each build also receives a newly generated signing certificate, frustrating detections that rely on a known certificate or an exact file signature.
The malware then asks the user to grant Android Accessibility access. This powerful permission can read interface content and perform gestures on the user’s behalf. RemControl uses it to capture screens, log text, inspect visible controls and make taps or swipes under an operator’s direction.
Dynamic overlays target banking credentials
When the victim opens a bank app on the target list, RemControl places a counterfeit interface over the legitimate application. Information entered into that screen is sent to the operator. The overlay then closes, revealing the real app and potentially leaving the victim to interpret the interruption as a harmless error.
The phishing screens are delivered from attacker infrastructure rather than embedded permanently in the Android package. Operators can therefore add banks, revise branding and adjust fields without convincing victims to install a new version. The trojan retrieves server-location information through Telegram, providing another way to redirect infected devices when infrastructure changes.
RemControl can also reconstruct information needed to infer an unlock pattern, stream screenshots and obstruct removal by pushing users away from settings screens. These functions allow a criminal to monitor activity, capture authentication data and interact with applications in real time, increasing the risk of fraudulent transfers.
AI traces appeared in the criminal backend
Investigators found documentation that described stolen bank details as quiz answers and framed remote access as parental monitoring. A complete AI-assistant response, including explanatory notes and an offer to produce more content, was left inside a live phishing page. The artifacts suggest that an AI assistant helped develop parts of the platform after being given a misleading description.
The malware itself is not using artificial intelligence on the phone. The security significance is that general-purpose coding assistance may lower the effort required to build dashboards, phishing templates and supporting infrastructure. The core attack still depends on social engineering, dangerous permissions and convincing overlays.
An affiliate-style control panel supports scale
An exposed operator panel offered functions for generating application builds, managing infected devices and reviewing captured credentials. Researchers associated observed samples with an affiliate label called UNKK. A possible link to another banking-malware ecosystem remains unproven, so it should not be treated as established attribution.
The panel and remotely updated overlays resemble a malware-as-a-service model in which a platform operator supplies tooling to separate criminals. That structure can accelerate regional campaigns because affiliates can customize delivery while relying on shared device-control and credential-collection systems.
How Android users can reduce the risk
- Install applications only through the official store or a vendor’s verified distribution channel.
- Treat requests for VPN, Accessibility or permission to install other apps as high risk.
- Leave any banking screen that appears unexpectedly and reopen the app from its normal icon.
- Use Play Protect and keep Android and financial applications updated.
- If infection is suspected, disconnect the device, contact the bank using a trusted number and seek professional help before restoring access.
RemControl succeeds by making each stage appear routine: a streaming download, an update, a permission prompt and finally a familiar bank screen. Breaking that sequence at the installation or permission stage remains the most reliable defense.
Leave a Reply
You must be logged in to post a comment.