RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
infosecurity-magazine.com Sep 25, 2026

RemControl Banking Trojan Gives Attackers Remote Control of Android Devices

AI-summarised brief · reviewed before publication

Group‑IB researchers have identified a new Android banking trojan, dubbed RemControl, that exploits Accessibility Services to seize full control of victims’ devices and harvest banking credentials such as PINs, mobile‑banking codes and card expiry dates. First seen in July 2026, the malware has targeted retail‑banking customers in Western Europe, the Middle East and Canada, compromising more than 30 banks across six countries. Distributed via counterfeit Google Play pages masquerading as the TVTap IPTV app, the dropper bypasses Google Play Protect by routing traffic through a null VPN and signing the payload with a freshly generated keystore key. The trojan’s developer, tracked as UNKK, used an AI assistant to generate much of the command‑and‑control infrastructure, mistakenly framing the API as a parental‑monitoring tool. The exposed C2 API documentation allowed researchers to map the full fraud platform, which supports multiple languages and may expand further.

💡 Why It Matters

  • · By hijacking Accessibility Services, RemControl can silently execute transactions, turning ordinary smartphones into covert banking fraud machines.
  • · Its AI‑crafted backend shows how threat actors can accelerate weaponisation, raising the bar for mobile security defenses.