A newly identified Android malware-as-a-service platform named RemControl is targeting banking users across Europe, Canada, and the Middle East through malvertising campaigns that impersonate the TVTap IPTV application, according to researchers at Group-IB.
The infrastructure has reportedly been active since at least May, with the first malware samples observed in July. Those samples contained more than 30 phishing overlays designed to harvest banking credentials from victims in Italy, France, Spain, Poland, Portugal, and other affected countries. One overlay reportedly displayed an AI assistant response, suggesting the phishing kit was built with help from AI models.
Distribution and Evasion
RemControl is distributed through fake Google Play landing pages that mimic the TVTap app. At least one Italian campaign used geofencing and mobile user-agent checks to filter targets, and the malicious download sites contained Meta Pixel tracking IDs, which Group-IB believes indicates abuse of Meta’s advertising ecosystem to funnel victims toward the fake pages.
Once launched, the dropper starts a VPN service that blocks traffic to Google Play services, preventing Play Protect from performing real-time malware checks. This technique has also recently appeared in the ToxicPanda malware family, a larger operation with phishing overlays covering 349 financial and cryptocurrency apps across 16 countries.
Capabilities
RemControl requests Accessibility Service permissions during installation. If granted, the malware can display full-screen phishing overlays over legitimate banking apps to steal PINs, card details, and login credentials, receive new banking targets dynamically from its command-and-control infrastructure, and stream live screenshots and the full Android UI tree to operators.
- Record clicks, text input, and focus events across apps
- Remotely perform taps, swipes, gestures, and text injection
- Capture pattern-lock coordinates on Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android devices
- Detect and block removal attempts by exiting when victims open accessibility or factory-reset settings
RemControl retrieves encrypted command-and-control information from Telegram channels, allowing operators to rotate infrastructure quickly if disrupted. Group-IB also found exposed FastAPI documentation on an early C2 proxy that revealed endpoints used to deliver overlays and collect stolen data.
Attribution
The identity of the threat actor remains unclear, but researchers found Russian-language text in some overlay HTML files, pointing to a Russian-speaking developer. Based on shared identifiers, Group-IB tracks the operator as UNKK and suspects a possible link to the Medusa banking trojan.
Users are advised to avoid installing APK files from outside Google Play, keep Play Protect scans enabled, and decline Accessibility Service permission requests from apps that do not legitimately need them.
