Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-28 · updated: 2026-09-28 · tags: [incident, financial-services, android, phishing] · confidence: high · severity: low · affected_sectors: [financial-services] · au_impact: true

Group-IB has documented RemControl, an Android banking trojan that abuses Android's Accessibility Service to take full remote control of victim devices and harvest credentials — PIN codes, mobile banking codes and card expiry dates — from customers of more than 30 banking institutions across six countries in Western Europe, the Middle East and Canada since July 2026. Victims are lured through fake Google Play Store pages impersonating the TVTap IPTV application, localised by user-agent and IP geolocation; a WebView imitating a TVTap update screen leads to a dropper that suppresses Google Play Protect by routing its traffic through a local null-VPN channel — a technique Group-IB describes as a recurring pattern in Android dropper development — and generates a fresh signing key in the Android Keystore to sign its own payload, defeating hash-based detection. Once installed, the payload requests Accessibility Service permission, and on grant it inflates a full-screen WebView overlay that covers the legitimate banking application and collects credentials per targeted institution; it also captures the screen as a machine-readable map of every visible UI element with coordinates, text and interactive state, logs keystrokes and captures the unlock pattern. Self-preservation functions block application removal and the factory-reset screen. Captured data is sent over a WebSocket using a JSON envelope, with a Telegram dead-drop hiding the real command-and-control address behind a second layer. The detail that lifts this above routine mobile-fraud reporting is the developer: Group-IB assesses the operator, tracked as UNKK and believed Russian-speaking, used an AI assistant to build significant portions of the C2 backend and phishing overlays, having apparently convinced the model that the API endpoints it was creating served a parental-monitoring app — with the resulting platform's own documentation describing credential theft as "quiz completion" and banking victims as "a person staring at the quiz". The C2 panel's API documentation was inadvertently exposed during analysis, giving the researchers the infrastructure map. Group-IB's blog was published 23 September and the malware is multilingual, which the researchers read as intent to expand into further regions.

Attribute Detail
Sector Financial Services
Date 2026-09-28
Source Group-IB
Reliability Tier 1