A New Wave of Android Malware Targets European and Canadian Users with Sophisticated Phishing Overlays
A highly advanced Android banking malware platform has been discovered, targeting users in Europe, Canada, and several Middle Eastern countries. Dubbed RemControl, this malware-as-a-service (MaaS) uses a combination of artificial intelligence (AI), malvertising campaigns, and phishing overlays to steal sensitive financial information from victims’ devices.
RemControl’s primary attack vector involves impersonating the popular TVTap IPTV application on fake Google Play pages. These malicious sites use geofencing and mobile User-Agent checks to ensure that only users in targeted regions are directed to the download page. Once a user clicks on the fake app, they’re presented with a phishing overlay designed to resemble an AI-powered assistant response.
This overlay is a strong indication that RemControl has been built using AI models, making it a sophisticated and potentially devastating threat. When launched, the malware starts a VPN service that blocks traffic from Google Play services, preventing real-time checks by Play Protect against known malware. This feature is similar to one observed in the recent ToxicPanda malware operation.
RemControl’s capabilities are extensive and alarming. Upon installation, the malware requests Accessibility Service permissions, which it uses to perform various actions on the victim’s device. These include displaying full-screen phishing overlays on top of legitimate banking apps, stealing sensitive financial information, and capturing Android pattern-lock coordinates across multiple OEMs.
The malware also has the ability to dynamically receive new banking targets from its command-and-control (C2) infrastructure and stream screenshots and UI tree data to the operator in real-time. Remotely, it can perform taps, swipes, scrolling, gestures, long presses, and text injection, effectively taking control of the victim’s device.
Researchers at Group-IB discovered that RemControl retrieves encrypted C2 information from Telegram channels, allowing the threat actor to rotate infrastructure dynamically in case of disruptions. The team also found FastAPI documentation exposed in the initial C2 proxy, revealing the endpoints used by the malware to fetch banking overlays and submit stolen credentials.
While the origin of the threat actor behind RemControl is unclear, researchers suspect a connection to the Medusa banking trojan based on a common identifier in the analyzed samples. The presence of Russian language in some overlay HTML files suggests that at least some of the developer’s code was written by a Russian speaker.
To protect themselves from this highly advanced malware, Android users are advised to exercise caution when downloading APK files outside of Google Play and decline Accessibility Service permission requests from apps that don’t require them for accessibility purposes. Regular Play Protect scans can also help detect and prevent RemControl infections. As the threat landscape continues to evolve with AI-powered attacks, it’s essential for users and organizations to stay vigilant and adapt their security strategies accordingly.
Source: Bleeping Computer — 2026-09-23