Particle.news

RemControl Malware Targets Android Users With Fake Play Pages

Researchers say targeted Meta ads, fake Google Play pages, a local VPN, AI-built overlays let attackers steal bank PINs.

Overview

  • Security firm Group-IB disclosed RemControl in late September after tracing infrastructure active since May and the first malware samples submitted in July 2026.
  • Operators lure victims to sideloaded APKs by using geofenced fake Google Play pages that impersonate the TVTap IPTV app and by deploying Meta Pixel tracking in ad funnels.
  • If a user grants Android Accessibility permissions, RemControl can show full-screen phishing overlays, stream screens, record taps and keystrokes, capture pattern locks, and remotely control the device to harvest banking PINs and card data.
  • The malware uses a local VPN to block Google Play Protect, generates a unique signing key per install, encrypts code with a custom packer, and fetches rotating C2 addresses from encrypted Telegram posts, while exposed FastAPI docs lower the barrier for affiliates.
  • Researchers say the platform is offered as malware-as-a-service and targets customers of more than 30 banks across parts of Europe, Canada and Gulf states, so users should avoid sideloading apps, deny unnecessary Accessibility rights, and keep Play Protect and OS updates enabled.