New Android Trojan 'RemControl' Hijacks Devices to Steal Banking Details
Security researchers at Group-IB have identified a new Android banking trojan called RemControl that abuses Android's Accessibility Services to take remote control of infected devices. Once installed, it can capture PIN codes, mobile banking codes and card expiry dates. Since July 2026, it has targeted customers of more than 30 banking institutions across six countries in Western Europe, the Middle East and Canada, and its multi-language support suggests it could expand further.
Victims are tricked into installing the malware through fake Google Play Store pages that impersonate the TVTap IPTV app. These pages adapt to the visitor's location and language. Once downloaded, a fake update screen prompts the user to install the malware, which then launches a local VPN service designed to block Google Play Protect from detecting it, a technique researchers say is becoming increasingly common in Android malware.
Group-IB also found evidence that the malware's developer, tracked as UNKK, may have used an AI assistant to help build parts of the command and control infrastructure and phishing overlays, possibly by disguising the project as a parental monitoring app. Exposed documentation referred to credential theft as a 'quiz' and victims as people 'staring at the quiz', giving researchers unusual insight into the operation.