# What happened Researchers at Group-IB uncovered a new Android banking trojan called RemControl that has been active since July 2026. The malware targets retail banking customers across Western Europe, the Middle East and Canada and can take remote control of infected devices to harvest banking credentials.
# How victims are lured and infected RemControl infections begin with fake Google Play Store pages that impersonate the TVTap IPTV application. These malicious pages adapt to the visitor's language and location using the browser user-agent and IP geolocation.
If the victim downloads and taps an apparent "install" button on a WebView-based interface, a dropper runs and performs several stealthy actions before installing the trojan:
- It launches a local VPN service that routes traffic for Google Play Protect through a null VPN channel, suppressing Play Protect checks.
- It generates a fresh signing key inside the Android Keystore and uses that key to sign the RemControl payload, helping evade hash-based detection.
After the payload installs, it immediately requests Accessibility Service permissions. If the user grants those permissions, the malware gains wide-ranging control over the device.
# What RemControl can do on a compromised device With Accessibility Service access, RemControl can:
- Capture the device screen and produce a machine-readable map of visible UI elements (coordinates, text and interactive states).
- Record keylogging and pattern lock input, tracking clicks, selection changes and unlock patterns.
- Prevent application removal and block factory reset screens to maintain persistence.
Captured information is packaged and sent using a Telegram dead-drop mechanism that hides the real command-and-control address. The primary live channel between infected phones and the operators is a WebSocket connection that exchanges JSON messages with fields such as cmd, udid, rid and data.
# Developer and infrastructure details
# Practical advice for Android banking customers Group-IB recommends straightforward defensive steps:
- Do not click suspicious links in email, SMS or social media.
- Treat unexpected permission requests, especially Accessibility Service access, as suspicious and deny them.
- Never enter banking PINs, mobile banking codes or card details into screens that appear unexpectedly while using your device.
# Why this matters RemControl combines established Android dropper techniques—Play Protect suppression via local VPN, re-signing payloads and Accessibility Service abuse—with overlays and screen capture to exfiltrate high-value banking data. Its targeting of more than 30 banks across multiple regions and multi-language support indicate the platform is already operational and positioned to expand.