A newly discovered Android banking trojan, named RemControl by its operator, has been targeting retail banking customers in Western Europe, the Middle East and Canada since July 2026. Group-IB researchers said they had confirmed targeting of more than 30 banking institutions across six countries. The malware supports multiple languages, potentially enabling expansion into other regions.
Its suspected Russian-speaking operator, tracked as UNKK, appears to have used an AI assistant to help create parts of the command-and-control backend and phishing overlays. Group-IB identified the infrastructure after API documentation for RemControl’s control panel was inadvertently exposed.
Victims are directed to fake Google Play pages impersonating the TVTap IPTV application. A dropper then displays a fraudulent update screen, attempts to suppress Google Play Protect by routing its traffic through a null VPN channel, and generates a new Android Keystore signing key to sign the payload. If installed, RemControl immediately requests Accessibility Service access.
When granted, this can allow the operator to control the device, capture screen content and key presses, record unlock patterns, and display full-screen WebView overlays that collect banking PINs, mobile banking codes and card expiry dates. The malware can also obstruct removal and factory-reset screens. Stolen information is sent using a Telegram dead-drop mechanism, with a WebSocket as the primary communications channel.
Group-IB advised Android users to install apps only from official platforms, avoid suspicious links, treat unexpected Accessibility Service requests with caution and never enter banking details into an unexpected screen.