MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via BleepingComputer

RemControl Android trojan spreads via fake IPTV app, steals banking data across Europe and Canada

Image via BleepingComputer
Image via BleepingComputer

A new Android malware-as-a-service operation named RemControl is being distributed through malicious ads impersonating the TVTap IPTV app, with phishing overlays for over 30 banking apps. The malware disables Google Play Protect by starting a VPN service, then requests Accessibility permissions to capture credentials, stream screens, and remotely control devices. Group-IB researchers say the campaign targets users in Europe, Canada, and the Middle East, and the overlays show signs of AI-assisted development.

Expanded Detail

The RemControl operation has been active since May, with samples first appearing in July. Group-IB identified over 30 phishing overlays targeting banking apps across Europe, Canada, and the Middle East. The malware's distribution relies on fake Google Play pages and Meta Pixel tracking, suggesting abuse of advertising platforms.

Notably, the malware retrieves encrypted C2 information through Telegram channels, allowing dynamic infrastructure rotation. Researchers found Russian language in overlay HTML files, pointing to a Russian-speaking developer, and they track the operator as UNKK, suspecting ties to the Medusa banking trojan.

Context

This malware could significantly impact everyday Android users who download apps outside official stores. Victims may face drained bank accounts and stolen credentials, with limited recourse. The malware-as-a-service model could lower the barrier for less skilled criminals, potentially expanding the threat landscape. However, awareness and cautious behavior—avoiding third-party APKs and denying unnecessary accessibility permissions—may substantially reduce individual risk.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Researchers show privileged attackers can hijack MFA flows to capture plaintext passwords · Cybersecurity
Global probe ties North Korean group to mass device compromise and crypto theft · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “New RemControl Android banking malware targets users in Europe and Canada.” Browse more stories.