Threat intel
RemControl: a fake TV app that steals bank PINs
New Android banking trojan RemControl poses as the TVTap IPTV app, fakes 30+ bank logins and blocks removal. How it works and how to clean a phone.
Group-IB disclosed RemControl on September 23, a previously undocumented Android banking trojan sold as malware-as-a-service (MaaS), meaning one operator builds and hosts it and affiliates rent it to run their own campaigns. It targets customers of more than 30 retail banks in Italy, France, Spain, Poland, Portugal, Canada and several Gulf Cooperation Council (GCC) states. Its command server domain was registered on May 12, 2026, and the first sample reached VirusTotal on July 19.
Victims install it themselves, believing they are getting TVTap, a popular IPTV (internet TV streaming) app that is not on Google Play. People who want TVTap are already used to fetching it from unofficial sites, so a convincing fake Play Store page does not look out of place to them. Anyone who has installed TVTap from outside Google Play since July, or who carries a personal Android phone with banking apps in one of the targeted countries, should read the checks below.
How it works
The victim first installs a dropper, a small installer whose only job is to install the real payload. It asks permission to start a VPN service, which Android lets any app do, routing the phone's traffic through the app itself. RemControl uses that position to drop all traffic from com.android.vending, the Play Store app that also runs Google Play Protect scanning, so the payload installs unchecked. The dropper then generates a fresh signing certificate on the device and signs the payload with it, so every install has a different certificate and file hash and blocklists built on either never match.
The payload then asks for Accessibility Service access. Accessibility exists so screen readers and switch controls can read what is on screen and act for the user. RemControl uses it to watch which app is in the foreground, record every text field change with millisecond timestamps (a keylogger, in effect), and inject taps, swipes, long presses and typed text. Group-IB found code that captures the unlock pattern grid on more than ten Android lock screen implementations, including Samsung One UI, Xiaomi MIUI, Huawei, OPPO ColorOS, OnePlus and stock Android.
When a targeted banking app opens, RemControl draws a full-screen WebView, an embedded browser, over it. The fake login is an HTML page the operator can change from the panel without shipping a new APK, and whatever the victim types into it goes to the attacker.
Remote control runs over a WebSocket, a persistent two-way connection, with an HTTP POST fallback. The phone streams its screen as WEBP images alongside the accessibility tree as JSON, the structured list of every button and field on screen, so the operator can click by element rather than by coordinate. The C2 (command and control) address is never stored in the app: RemControl reads an AES-encrypted string from two public Telegram channels and decrypts it, so the operator can move servers without rebuilding anything.
Removal is blocked through the same Accessibility access. RemControl watches for the screens used to uninstall apps, revoke Accessibility permissions or factory reset the phone, with the screen titles matched in more than 30 languages, and fires a Back action before the victim can tap anything. To the user, Settings simply seems to close by itself.
What attackers are doing
Group-IB tracks the operator as UNKK, a tag hardcoded in every sample it analysed. Russian-language comments in overlay HTML suggest a Russian-speaking developer. The name is one letter off UNKN, an affiliate of the Medusa banking trojan, and RemControl shares Medusa's habit of hiding C2 addresses in Telegram, but Group-IB stops short of a firm link. Public reporting does not name the individual banks.
In the campaign Group-IB traced, paid Meta ads led to six Italian websites hosting fake Google Play pages. They served the APK only to visitors with an Italian IP address and a mobile browser, hiding it from researchers browsing from elsewhere or from a desktop. The operator panel, whose API documentation was left publicly exposed, can generate a new APK per affiliate with its own lure page, app name, Accessibility label and package name, so the "TVTap" disguise is one option among many.
Group-IB's claim that AI helped build RemControl comes from two artifacts. The exposed API documentation describes the endpoints that serve bank overlays and receive stolen credentials as handling "quiz answers" and "quiz screens", and calls the remote control features "parental monitoring". Group-IB reads this as the developer describing the project to an AI assistant as a harmless parental control app, so it would write the C2 backend and overlay pages. One overlay served to real victims still contained the assistant's full reply pasted at the bottom, with implementation notes, a summary of changes and an offer to make further adjustments. The practical effect is speed: bank-specific overlays can be generated and revised quickly, so a MaaS operator can add banks and fix unconvincing screens without a skilled developer, and affiliates need even less.
What to do
On a managed Android fleet, set the mobile device management (MDM) policy that blocks installs from unknown sources, and use Android Enterprise's permitted Accessibility services list so only named assistive apps can hold that access. Tell staff that IPTV and streaming apps from outside Google Play are the lure here, and that a "Google Play" page reached from an ad or search result is fake.
Treat two prompts as a hard stop: a new app asking to start a VPN when it is not a VPN you chose, and any non-assistive app asking for Accessibility. RemControl needs both, in that order.
To check a phone:
- Open Settings, Accessibility, then Installed apps or Downloaded apps (the wording varies by manufacturer). Every entry should be something you recognise. The label is configurable per build, so do not look only for "TVTap".
- Look for a key icon in the status bar, or check Settings, Network and internet, VPN. An active VPN you did not set up is a strong sign.
- Open the Play Store app, tap your profile icon, then Play Protect. A scan that fails or shows no recent check deserves attention.
- Watch for Settings closing on its own when you open Apps or Accessibility. That is RemControl's removal block at work.
If a phone shows these signs, call the bank from a different phone first and freeze card and online banking access. Then boot into Safe Mode (on most phones, press and hold "Power off" in the power menu), which starts Android with downloaded apps and their Accessibility services disabled, and uninstall the fake app and any unknown VPN or Accessibility app. If Settings still bounces you out, or the app comes back, factory reset from recovery mode or remotely from Google's Find Hub; neither goes through the Settings screens the malware watches. The operator had live control, the unlock pattern and banking credentials, so a reset is the safer default even when Safe Mode removal appears to work. Change banking passwords, PINs and the unlock pattern from a clean device, since anything typed on the infected phone reaches the operator.
For banks and fintechs whose apps sit on the target list, Group-IB recommends user session monitoring that detects malware on the device before the customer enters credentials.
Our mobile penetration testing team tests how your Android app behaves under overlay and Accessibility abuse, and our safeguarding and hardening engineers set the MDM policies that keep unknown installs, rogue VPNs and Accessibility grants off company devices. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Group-IB, Help Net Security, BleepingComputer, Infosecurity Magazine, GBHackers, Cybersecurity News, Android Headlines.