New RemControl Android Banking Trojan Spreads via Fake IPTV App on Meta Ads
Security researchers at Group-IB have uncovered a previously unknown Android banking trojan named RemControl, targeting retail banking customers across Western Europe, the Middle East and Canada. The malware spreads through fake web pages that impersonate the TVTap IPTV application, with victims lured in via Meta advertising rather than the official Google Play Store.
Once installed, RemControl abuses Android's Accessibility Service to overlay fake phishing screens on top of genuine banking apps, capture keystrokes, stream the victim's screen in real time and hand attackers full remote control of the device. Its command and control address is hidden inside encrypted Telegram messages, letting operators rotate infrastructure easily without needing to update the malware itself. Researchers found evidence of AI assisted development in the malware's phishing pages and operator tools, along with Russian language code comments, and noted possible links to the Medusa UNKN affiliate botnet.
This case is a reminder that mobile malware increasingly relies on convincing fake apps and legitimate ad platforms rather than technical exploits alone. Businesses whose staff use personal or work Android devices for banking or company logins should be aware that accessibility permissions can be abused to bypass normal app protections.
Key Takeaway: Only install apps from official app stores, avoid granting Accessibility Service permissions to unfamiliar apps, and educate staff about ad-based scams that mimic popular apps.