A new and highly advanced Android malware-as-a-service (MaaS) has emerged, using popular IPTV apps as bait to gain access to users’ devices and then steal banking data. RemControl, as it has been named by researchers Group-IB, is distributed through malicious advertising campaigns that mimic the IPTV app TVTap and targets users in Europe, Canada, and countries in the Middle East.

The company's infrastructure appears to have been in operation since at least May 2026, with the first malware samples recorded in July. From initial analysis, researchers identified more than 30 phishing overlays, which appear on top of legitimate applications and are designed to steal PINs, passwords, and other sensitive banking information.
The bait is a fake version of TVTap
The attack starts with a fairly simple technique: the user searches for the TVTap IPTV and is directed to a website that looks like an official Google Play. In reality, it is a malicious page hosting the RemControl APK.
The choice of TVTap is not accidental. It is an application that is not officially available through Google Play, as a result of which many users are already accustomed to installing APKs from external sources. This creates an ideal environment for attackers, as the installation process outside the official store can be presented as something normal.
See also: Corp MDM malware targets Logistics companies, steals new SMS and redirects calls
In a campaign targeting Italy, researchers found geofencing and User-Agent checksto ensure the malicious APK was only served to visitors who met certain criteria. The pages also contained a Meta Pixel, which Group-IB believes indicates that the attackers may have been leveraging Meta’s advertising ecosystem to direct users to download pages.
The VPN that blocks Play Protect
One of the most interesting features of RemControl is already in the installation stage. The dropper asks the user to enable a VPN, presenting it as a necessary step in the process.
In fact, the feature is used to prevent the Google Play Store from communicating with services required for Google Play Protect. In this way, the malware tries to prevent security mechanisms from performing the necessary checks in real time. A similar technique has been observed in a recent version of ToxicPanda, which shows that certain defense-against-defense techniques are starting to be reused by different Android malware campaigns.
RemControl also uses a different signing certificate per installation, which makes detection mechanisms that rely solely on hashes or known certificates difficult.
The dangerous Accessibility Services permission
After installation, RemControl requests access to Services Accessibility. This is an Android feature designed to help people with disabilities interact with the device, but it has become particularly attractive to mobile banking trojans.
Once the user grants permission, RemControl can gain extremely broad control over the device. It can display fake login screens over real banking apps, collect PINs, mobile banking codes, and card expiration dates, and dynamically receive new targets from the command-and-control server.
See also: EvilTokens: Microsoft dismantles AI-powered phishing platform
The capabilities don't stop at stealing credentials. The malware can stream screenshots in real time, record keystrokes and text input, and allow the remote operator to perform taps, swipes, scrolls, and other actions on the device.
Even more worrying is the ability to record the coordinates of the pattern unlock, while the malware also has self-protection mechanisms. If it senses that the user is trying to uninstall it or revoke its privileges, it can automatically remove the relevant settings screen.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Telegram is used for C2 change
RemControl's communication infrastructure is designed to be scalable without requiring a new version of the malware. The malware retrieves encrypted information about the C2 server from Telegram channels, allowing operators to move their infrastructure to different servers.
This technique makes it difficult to simply block a specific address. Even if a C2 server is detected and taken down, operators can still notify the point of contact through existing infrastructure.
Artificial intelligence seems to have helped the development
Of particular interest is the use of artificial intelligence in the development of the infrastructure. Group-IB identified an AI assistant response in one of the phishing overlays that had remained in the code, while technical analysis of the infrastructure showed evidence that AI models were used to create parts of the backend and fake screens.
This has broader implications for cybersecurity. Using AI can reduce the time and technical expertise required to produce phishing templates and malware infrastructure, allowing attackers to create or adapt new campaigns more quickly.
Possible connection to Medusa
The identity of the RemControl operators has not been confirmed. Group-IB is tracking the operator under the name UNKK, based on a common affiliate identifier found in the samples.
See also: AI malware removes humans from the attack chain
Researchers are looking into a possible connection to the Medusa, as there are similarities in dropper nomenclature, distribution techniques, use of Telegram for C2, and targeting of European financial institutions. However, the research itself treats the connection as an indication rather than a definitive attribution.
What Android users should watch out for
RemControl shows how dangerous the combination of sideloading, malvertising, and excessive permissions. Android users should avoid APKs from unknown websites and not assume a page is safe just because it visually resembles Google Play.
Particular caution is needed when an app requests Accessibility Services for no apparent reason, but also when an installer asks to enable VPN. Play Protect should remain active and users should carefully review any installation or additional permission requests.
RemControl is a typical example of the evolution of Android banking trojans: from simple password-stealing tools, they transform into complete remote control platforms, capable of monitoring the screen, emulating banking applications, and interacting with the device almost like a real user.
source: www.bleepingcomputer.com
