Security warning: fake app links on WhatsApp and Telegram can steal money and data

Security experts are warning that manipulated links and APK files spread through messaging services like WhatsApp and Telegram can install malware and compromise sensitive data. At Gisec Global 2026, researchers advised users to install apps only from official stores and recommended runtime protection and AI-based security tools for companies. The report also describes the Android banking trojan RemControl, which uses accessibility services to overlay more than 30 banking apps and stream screen content.
. Plain text. No markdown? Fine. Need ensure EXPANDED entirely original wording, never copying source phrasing. We paraphrased. Some terms unavoidable: Gisec Global 2026, Protectt.AI, Group-IB, RemControl, IPTV, Meta, accessibility services, Samsung etc. That's okay. "runtime self-protection" maybe source "Runtime-Application-Self-Protection" but paraphrased. "AI security" okay. "official stores" source "offizielle Quellen". Fine. "fake IPTV pages" source "gefälschte IPTV-Seiten". Fine. "overlay over 30 banking apps" source "Overlays über mehr als 30 Banking-Apps". Fine. "streams screens" source "Bildschirminhalte live zu streamen". Fine. "extracts unlock codes" source "Entsperrcodes extrahieren". Fine. "Deep-link phishing" source. "attacker-controlled WebView" source "vom Angreifer gesteuerte WebView-Seite". Fine. "Chinese victim lost 8,000 yuan" source. "Chandigarh victims lost over 6 lakh rupees" source. "Ahmedabad couple lost 20 lakh rupees" source. "government-program disguise ac