A New Android Malware Threat Erupts in Europe and Canada, Targeting Banking Credentials with Sophisticated Tactics
Cybersecurity researchers have uncovered a new Android malware-as-a-service (MaaS) platform called RemControl, which is wreaking havoc on users in Europe and Canada. This highly sophisticated threat exploits vulnerabilities in the TVTap IPTV application to deliver phishing overlays designed to steal sensitive banking information.
RemControl’s operators are using malvertising campaigns that impersonate legitimate apps, including the popular TVTap IPTV app, to distribute their malware. The initial infection vector involves downloading a fake APK file from a malicious website, which then installs the RemControl dropper on the victim’s device. Once installed, the malware requests permission to run as an accessibility service, allowing it to display full-screen phishing overlays on top of legitimate banking apps.
But what makes RemControl particularly concerning is its use of AI-powered features. The malware can dynamically receive new banking targets from its command-and-control (C2) infrastructure and even stream screenshots and user interface data to the operator in real-time. This level of sophistication suggests that the threat actor behind RemControl has a strong technical background, possibly with ties to Russian-speaking developers.
RemControl’s operators have also demonstrated an ability to adapt and evade detection by using VPN services to block traffic from Google Play services, preventing real-time checks against known malware. The malware also exhibits self-preservation capabilities, automatically exiting when the user attempts to remove it or access settings that could compromise its operation.
Researchers at Group-IB discovered that RemControl retrieves encrypted C2 information from Telegram channels, allowing the operators to rotate their infrastructure dynamically in case of disruptions. Furthermore, FastAPI documentation was found exposed on the initial C2 proxy, revealing endpoints used by the malware to fetch banking overlays and submit stolen credentials.
While the origin of the threat actor behind RemControl remains unclear, researchers suspect a connection to the Medusa banking trojan, which has been linked to similar attacks in the past. Android users are advised to exercise extreme caution when downloading APK files from outside Google Play, as these apps may be infected with malware like RemControl.
To protect themselves from this and other threats, users should ensure that their devices run regular Play Protect scans and decline accessibility service permission requests from apps that do not require them for legitimate accessibility purposes. By taking proactive steps to secure their Android devices, users can reduce the risk of falling victim to sophisticated attacks like those perpetrated by RemControl’s operators.
Source: Bleeping Computer — 2026-09-23