More than 30 phishing overlays were present in the first observed samples of a new Android malware-as-a-service platform called RemControl, according to researchers who tracked the operation after infrastructure activity began in May and samples appeared in July.
How RemControl reaches victims: fake stores, malvertising, and ad signals
Researchers at cybersecurity company Group-IB describe RemControl as being distributed through fake Google Play pages that impersonate the TVTap IPTV application. The operator used malvertising campaigns that directed potential victims to those fake pages. At least one Italian campaign included geofencing and mobile User‑Agent checks to restrict who saw the malicious pages.
Group-IB also found Meta Pixel tracking IDs on the malicious sites; the researchers view those identifiers as an indicator that the operator abused Meta’s advertising ecosystem to drive traffic to the fake download pages.
Capabilities once installed: accessibility abuse, overlays, and persistence
When the RemControl dropper runs it requests Android Accessibility Service permissions. If granted, Group-IB says the malware can:
- Display full‑screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials
- Dynamically receive new banking targets from the command‑and‑control (C2) infrastructure
- Stream screenshots and the full Android accessibility/UI tree to the operator in real time
- Record clicks, text changes, focus events, and other user input across applications
- Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection
- Capture Android pattern‑lock coordinates across several OEMs, including Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android
- Prevent removal by detecting when victims enter application‑management, accessibility, or factory‑reset settings and automatically exiting

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildInfrastructure: Telegram, FastAPI exposure, and dynamic C2 rotation
Group-IB reports that RemControl retrieves encrypted C2 information from Telegram channels, a mechanism that lets the operator rotate infrastructure dynamically when parts of the network are disrupted. In the initial C2 proxy, the researchers found exposed FastAPI documentation that revealed the endpoints used by the malware to fetch banking overlays and to submit stolen credentials.
Geography, attribution signals, and the AI element in overlays
According to Group-IB, RemControl targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East. The origin of the threat actor remains unclear, but the researchers identified Russian language in the HTML files of some overlays, which they say indicates a Russian speaker developed at least some of those components. Based on a common identifier in analyzed samples, Group‑IB tracks the operator as UNKK and suspects a connection to the Medusa banking trojan.
One of the phishing overlays displayed an AI assistant response, a detail Group‑IB highlights as a strong indication that at least part of the overlay content was built using AI models.
What this means for technologists, advertisers, and end users
- Technologists and security teams: Monitor for indicators such as fake Google Play pages impersonating legitimate apps and FastAPI endpoints exposed on C2 proxies; pay attention to attempts to block Play Protect by a VPN service started by an installer.
- Advertisers and platform operators: The presence of Meta Pixel tracking IDs on malicious pages suggests advertising ecosystems can be abused to steer traffic to fraudulent installers; ad buyers and platform defenders should investigate whether campaign signals are being misused.
- End users: Group‑IB advises avoiding downloading APK files from outside Google Play unless the publisher is explicitly trusted, keeping regular Play Protect scans enabled, and declining Accessibility Service permission requests from apps that do not require them for genuine accessibility functions.
RemControl combines familiar mobile‑banking trojan techniques—phishing overlays and accessibility abuse—with modern tactics such as Telegram‑based encrypted C2 distribution and AI‑crafted overlay content, according to Group‑IB’s analysis. The operation’s use of geofencing, advertising signals, and a VPN‑style blocker for Google Play services makes detection and remediation more difficult for affected devices. For now, Group‑IB’s practical guidance—permission hygiene, Play Protect scans, and caution with APKs—remains the closest defense against this evolving MaaS threat.




