Overview
- Group-IB published a technical analysis in late September 2026 that revealed RemControl is an active malware‑as‑a‑service platform used to target retail banking customers.
- Operators steer victims to sideloaded APKs by serving fake Google Play pages for the TVTap IPTV app and using geofencing, mobile user‑agent checks, and Meta Pixel tracking in malvertising.
- A dropper launches a local VPN to block Google Play Protect, creates fresh signing keys to evade detection, and requests Android Accessibility permission so the payload can display overlays, capture taps and pattern locks, stream screenshots, and block removal.
- The malware discovers command‑and‑control addresses via encrypted Telegram channels and a WebSocket/JSON channel, and researchers found exposed FastAPI documentation plus an unedited AI assistant response inside a live phishing overlay.
- RemControl targets customers of more than 30 banks across Western Europe, Canada and some Gulf states, and users are advised to avoid sideloaded apps, refuse unexpected Accessibility requests, and install only from official app stores.