RemControl is a new Android banking trojan that lures victims with fake TVTap app pages, then abuses permissions to take over devices and steal banking PINs and other sensitive data. Group-IB found that it targets customers of more than 30 banks across several countries and appears to use AI-assisted infrastructure and malware-as-a-service delivery. #RemControl #GroupIB #TVTap #UNKK #UNKN #Medusa
Keypoints
- RemControl spreads through fake Google Play pages impersonating the TVTap IPTV app.
- It targets banking customers in Italy, France, Spain, Poland, Portugal, Canada, and Gulf states.
- The malware uses Accessibility Service and VPN abuse to gain control and evade Google Play Protect.
- RemControl can steal PINs, banking codes, card data, screenshots, and unlock patterns.
- Group-IB found signs of AI-assisted development, malware-as-a-service, and possible links to UNKN.
Read More: https://www.helpnetsecurity.com/2026/09/24/remcontrol-android-banking-trojan-fake-tv-app/