Back

RemControl Android Malware Platform Disclosed Targeting Multiple Regions

At a glance

  • Group-IB disclosed RemControl Android malware on 2026-09-23.
  • RemControl targets users in Europe, Canada, and the Middle East.
  • Malware distributed via fake TVTap app on fraudulent Google Play pages.

Group-IB researchers publicly disclosed the existence of a new Android malware-as-a-service platform named RemControl on September 23, 2026. The disclosure highlights the continued evolution of threats targeting mobile banking users across several regions.

RemControl has been active since at least May 2026, with initial malware samples observed in July 2026. According to Group-IB, the malware is distributed through malvertising campaigns that impersonate the TVTap IPTV application, using fraudulent Google Play pages to lure victims.

The platform targets users in specific European countries, including Italy, France, Spain, Poland, and Portugal, as well as Canada and various Middle Eastern countries. The malware employs over 30 phishing overlays designed to capture banking credentials from affected users.

RemControl’s dropper initiates a VPN service that blocks Google Play services, which is intended to bypass Play Protect security features. Once the malware is granted Accessibility Service permissions, it can display phishing overlays, stream screenshots and user interface data, record interactions, perform remote gestures, capture pattern-lock coordinates, and prevent removal from infected devices.

What the numbers show

  • RemControl was publicly disclosed on 2026-09-23.
  • Malware activity traced back to at least May 2026.
  • Over 30 phishing overlays included in the platform.

The malware retrieves encrypted command-and-control configuration from Telegram channels, enabling dynamic changes to its infrastructure. Group-IB researchers identified exposed FastAPI documentation on the initial command-and-control proxy, which revealed endpoints used for fetching overlays and submitting stolen credentials.

Some of the overlay HTML files analyzed by Group-IB contained Russian language, which suggests that a Russian speaker may have contributed to the malware’s development. Researchers track the operator of RemControl under the alias “UNKK” and have noted a suspected connection to the Medusa banking trojan.

Group-IB’s findings provide detailed insight into the technical methods and distribution tactics used by RemControl. The disclosure underscores the need for ongoing vigilance among mobile users in the targeted regions.

* This article is based on publicly available information at the time of writing.