RemControl Android trojan spreads via fake IPTV app, steals banking data across Europe and Canada

A new Android malware-as-a-service operation named RemControl is being distributed through malicious ads impersonating the TVTap IPTV app, with phishing overlays for over 30 banking apps. The malware disables Google Play Protect by starting a VPN service, then requests Accessibility permissions to capture credentials, stream screens, and remotely control devices. Group-IB researchers say the campaign targets users in Europe, Canada, and the Middle East, and the overlays show signs of AI-assisted development.
The RemControl operation has been active since May, with samples first appearing in July. Group-IB identified over 30 phishing overlays targeting banking apps across Europe, Canada, and the Middle East. The malware's distribution relies on fake Google Play pages and Meta Pixel tracking, suggesting abuse of advertising platforms.
Notably, the malware retrieves encrypted C2 information through Telegram channels, allowing dynamic infrastructure rotation. Researchers found Russian language in overlay HTML files, pointing to a Russian-speaking developer, and they track the operator as UNKK, suspecting ties to the Medusa banking trojan.
This malware could significantly impact everyday Android users who download apps outside official stores. Victims may face drained bank accounts and stolen credentials, with limited recourse. The malware-as-a-service model could lower the barrier for less skilled criminals, potentially expanding the threat landscape. However, awareness and cautious behavior—avoiding third-party APKs and denying unnecessary accessibility permissions—may substantially reduce individual risk.