Infosecurity Magazine iconInfosecurity MagazineSep 25, 2026 ~5 min source read

RemControl Android Trojan Uses Accessibility Service to Take Remote Control and Steal Banking Credentials

A newly discovered trojan called RemControl abuses Android Accessibility permissions, fake Google Play pages and overlays to capture PINs, mobile banking codes and card details across multiple countries since July 2026.

Share this story

Send the public story page.

Useful takeaways from this story.

RemControl gains full device control by convincing victims to grant Android Accessibility Service permissions immediately after installation.

Once active, RemControl uses full-screen WebView overlays, screen capture, keylogging and pattern-lock capture to harvest banking credentials and prevent app removal or factory reset.

# What happened Researchers at Group-IB uncovered a new Android banking trojan called RemControl that has been active since July 2026. The malware targets retail banking customers across Western Europe, the Middle East and Canada and can take remote control of infected devices to harvest banking credentials.

# How victims are lured and infected RemControl infections begin with fake Google Play Store pages that impersonate the TVTap IPTV application. These malicious pages adapt to the visitor's language and location using the browser user-agent and IP geolocation.

If the victim downloads and taps an apparent "install" button on a WebView-based interface, a dropper runs and performs several stealthy actions before installing the trojan:

  • It launches a local VPN service that routes traffic for Google Play Protect through a null VPN channel, suppressing Play Protect checks.
  • It generates a fresh signing key inside the Android Keystore and uses that key to sign the RemControl payload, helping evade hash-based detection.

After the payload installs, it immediately requests Accessibility Service permissions. If the user grants those permissions, the malware gains wide-ranging control over the device.

# What RemControl can do on a compromised device With Accessibility Service access, RemControl can:

  • Capture the device screen and produce a machine-readable map of visible UI elements (coordinates, text and interactive states).
  • Record keylogging and pattern lock input, tracking clicks, selection changes and unlock patterns.
  • Prevent application removal and block factory reset screens to maintain persistence.

Captured information is packaged and sent using a Telegram dead-drop mechanism that hides the real command-and-control address. The primary live channel between infected phones and the operators is a WebSocket connection that exchanges JSON messages with fields such as cmd, udid, rid and data.

# Developer and infrastructure details

# Practical advice for Android banking customers Group-IB recommends straightforward defensive steps:

  • Do not click suspicious links in email, SMS or social media.
  • Treat unexpected permission requests, especially Accessibility Service access, as suspicious and deny them.
  • Never enter banking PINs, mobile banking codes or card details into screens that appear unexpectedly while using your device.

# Why this matters RemControl combines established Android dropper techniques—Play Protect suppression via local VPN, re-signing payloads and Accessibility Service abuse—with overlays and screen capture to exfiltrate high-value banking data. Its targeting of more than 30 banks across multiple regions and multi-language support indicate the platform is already operational and positioned to expand.

More context around this story.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app