Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New RemControl Android banking malware targets users in Europe and Canada

    September 23, 2026

    Placeholder domain used in dev docs now serves ClickFix attacks

    September 23, 2026

    FBI Hack Exposed FBI’s Own Hacking Unit

    September 23, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»New RemControl Android banking malware targets users in Europe and Canada
    News

    New RemControl Android banking malware targets users in Europe and Canada

    adminBy adminSeptember 23, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    New RemControl Android banking malware targets users in Europe and Canada

    A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.

    Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials.

    Researchers at cybersecurity company Group-IB say that the malware targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East.

    In one of the overlays, the malware displays an AI assistant response, a strong indication that it has been built with the help of AI models.

    Phishing overlay exposing the use of AI
    Phishing overlay exposing the use of AI
    Source: Group-IB

    RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.

    The malicious sites include Meta Pixel tracking IDs, which Group-IB sees as a hint that the operator abused Meta’s advertising ecosystem to drive victims to the download pages.

    Fake Google Play site
    Fake Google Play site
    Source: Group-IB

    When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks against known malware.

    The feature has also been observed in a recent version of the ToxicPanda malware, a much bigger operation that uses phishing overlays for 349 financial, cryptocurrency, and digital wallets applications used in 16 countries.  

    phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.

    During installation, the malware requests approval for Accessibility Service permissions.

    Accessibility
    Source: Group-IB

    If the requested permissions are granted, RemControl can perform the following actions:

    • Display full-screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials
    • Dynamically receive new banking targets from the command-and-control (C2) infrastructure
    • Stream screenshots and the full Android accessibility/UI tree to the operator in real time
    • Record clicks, text changes, focus events, and other user input across applications
    • Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection
    • Capture Android pattern-lock coordinates across several OEMs, including Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android
    • Prevent removal by detecting when victims enter application-management, accessibility, or factory-reset settings and automatically exiting

    RemControl retrieves encrypted C2 information from Telegram channels, so it can rotate infrastructure dynamically in case of disruptions.

    Group-IB found FastAPI documentation exposed in the initial C2 proxy that revealed the endpoints the malware used to fetch banking overlays and to submit stolen credentials.

    The origin of the threat actor behind RemControl is unclear, but the researchers found Russian language in the HTML files of some overlays, indicating a Russian speaker as the developer of at least some of them .

    Based on a common identifier in the analyzed samples, the researchers track the RemControl operator as UNKK and suspect a connection to the Medusa banking trojan.

    Android users are advised to avoid downloading APK files from outside Google Play unless they explicitly trust the publisher.

    Regular Play Protect scans and declining Accessibility Service permission requests from apps that do not require them for accessibility purposes are also recommended security practices.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticlePlaceholder domain used in dev docs now serves ClickFix attacks
    admin
    • Website

    Related Posts

    News

    Placeholder domain used in dev docs now serves ClickFix attacks

    September 23, 2026
    News

    FBI Hack Exposed FBI’s Own Hacking Unit

    September 23, 2026
    News

    Americans Fear AI Will Make the World Worse, Love It Anyway

    September 23, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202642 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202642 Views
    Our Picks

    New RemControl Android banking malware targets users in Europe and Canada

    September 23, 2026

    Placeholder domain used in dev docs now serves ClickFix attacks

    September 23, 2026

    FBI Hack Exposed FBI’s Own Hacking Unit

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.