Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin Price Slips While US Treasury Yields Soar

    September 24, 2026

    Djibouti’s Refugee Crisis: What to Know as Houthi Attacks Ramp Up

    September 24, 2026

    Albanese says OpenAI hacked Medicare and told Australia months later via email to generic inbox | Medicare Australia

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin Price Slips While US Treasury Yields Soar
    • Djibouti’s Refugee Crisis: What to Know as Houthi Attacks Ramp Up
    • Albanese says OpenAI hacked Medicare and told Australia months later via email to generic inbox | Medicare Australia
    • Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices
    • New RemControl Android banking malware targets users in Europe and Canada
    • Circle’s Arc takes aim at the $10 trillion-a-day FX market
    • NASA Welcomes Croatia as Newest Artemis Accords Signatory
    • Trump’s Board of Peace Unveils $2.45 Billion Reconstruction Plan for Gaza
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New RemControl Android banking malware targets users in Europe and Canada

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.

    Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials.

    Researchers at cybersecurity company Group-IB say that the malware targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East.

    In one of the overlays, the malware displays an AI assistant response, a strong indication that it has been built with the help of AI models.

    Phishing overlay exposing the use of AI
    Phishing overlay exposing the use of AI
    Source: Group-IB

    RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.

    The malicious sites include Meta Pixel tracking IDs, which Group-IB sees as a hint that the operator abused Meta’s advertising ecosystem to drive victims to the download pages.

    Fake Google Play site
    Fake Google Play site
    Source: Group-IB

    When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks against known malware.

    The feature has also been observed in a recent version of the ToxicPanda malware, a much bigger operation that uses phishing overlays for 349 financial, cryptocurrency, and digital wallets applications used in 16 countries.  

    phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.

    During installation, the malware requests approval for Accessibility Service permissions.

    Accessibility
    Source: Group-IB

    If the requested permissions are granted, RemControl can perform the following actions:

    • Display full-screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials
    • Dynamically receive new banking targets from the command-and-control (C2) infrastructure
    • Stream screenshots and the full Android accessibility/UI tree to the operator in real time
    • Record clicks, text changes, focus events, and other user input across applications
    • Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection
    • Capture Android pattern-lock coordinates across several OEMs, including Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android
    • Prevent removal by detecting when victims enter application-management, accessibility, or factory-reset settings and automatically exiting

    RemControl retrieves encrypted C2 information from Telegram channels, so it can rotate infrastructure dynamically in case of disruptions.

    Group-IB found FastAPI documentation exposed in the initial C2 proxy that revealed the endpoints the malware used to fetch banking overlays and to submit stolen credentials.

    The origin of the threat actor behind RemControl is unclear, but the researchers found Russian language in the HTML files of some overlays, indicating a Russian speaker as the developer of at least some of them .

    Based on a common identifier in the analyzed samples, the researchers track the RemControl operator as UNKK and suspect a connection to the Medusa banking trojan.

    Android users are advised to avoid downloading APK files from outside Google Play unless they explicitly trust the publisher.

    Regular Play Protect scans and declining Accessibility Service permission requests from apps that do not require them for accessibility purposes are also recommended security practices.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Android banking Canada Europe Malware RemControl targets users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    Placeholder domain used in dev docs now serves ClickFix attacks

    IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    F5 fixes actively exploited zero-day flaw in BIG-IP APM

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin Price Slips While US Treasury Yields Soar

    September 24, 2026

    Djibouti’s Refugee Crisis: What to Know as Houthi Attacks Ramp Up

    September 24, 2026

    Albanese says OpenAI hacked Medicare and told Australia months later via email to generic inbox | Medicare Australia

    September 24, 2026

    Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin Price Slips While US Treasury Yields Soar

    September 24, 2026

    Djibouti’s Refugee Crisis: What to Know as Houthi Attacks Ramp Up

    September 24, 2026

    Albanese says OpenAI hacked Medicare and told Australia months later via email to generic inbox | Medicare Australia

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.