“With confirmed targeting of more than 30 banking institutions across six countries, it represents a serious threat to both banks and their customers,” Group-IB researchers wrote.
How RemControl seizes devices
RemControl begins its campaign with a familiar social-engineering move: fake Google Play Store pages that impersonate the TVTap IPTV application. According to Group-IB, those pages are tailored to the visitor’s user-agent and IP geolocation and present a WebView-based UI that mimics a TVTap update screen. If a victim clicks “install,” a dropper launches a chain of actions designed to block detection and install the banking trojan.
The dropper launches a local VPN service that routes traffic from Google Play Protect through a null VPN channel — a technique Group-IB highlights as a recurring pattern for suppressing Play Protect checks. It also generates a fresh signing key in the Android Keystore and uses that key to sign the RemControl payload before installation, a measure intended to evade hash‑based detection. Once installed, the payload immediately requests Android Accessibility Service permissions; if granted, those permissions give the malware full control over the device.
What RemControl can do once granted Accessibility access
With Accessibility Service privileges, RemControl can inflate full-screen WebView overlays that entirely cover the legitimate banking application from the victim’s point of view and collect credentials such as PIN codes, mobile banking codes and card expiry dates for the targeted institution. The trojan can also capture the device screen in a machine-readable form, mapping visible UI elements with coordinates, text content and interactive states.
Group-IB’s analysis found additional capabilities including keylogging and pattern-lock capture, tracking user clicks and unlock patterns, and self‑preservation functions that prevent application removal and interfere with factory reset screens. Those features combine to maintain persistent, stealthy access and to siphon the specific banking data RemControl’s operators target.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageOperator profile, AI use and exposed documentation
Group-IB attributes development of RemControl to an operator they track as UNKK, whom they describe as likely Russian-speaking. Their report says the developer appears to have used an AI assistant to construct significant parts of the command-and-control backend and the phishing overlays. According to Group-IB, the operator likely tricked the AI model by presenting the API endpoints as if they were for a parental monitoring application; consequentially, the platform’s own documentation euphemises credential theft as “quiz completion” and describes banking victims as “a person staring at the quiz.”
During analysis, the researchers found that the trojan’s C2 panel API documentation had been inadvertently exposed, which allowed them deep insight into the malware’s infrastructure and operational patterns.
Infrastructure: C2, communications and data exfiltration
RemControl’s primary command channel is a WebSocket connection. Messages are packed in a JSON envelope with fields named cmd, udid, rid and data. To obscure the true command-and-control endpoints, captured data is sent through a Telegram dead-drop mechanism that hides the real C2 address behind an additional layer.
The combination of a WebView-based overlay for credential collection, Accessibility-driven UI mapping and screen capture, plus a communications chain that includes a Telegram dead-drop and WebSocket messaging, creates a tightly integrated platform for remote control and banking fraud.
What this means for banking customers, security teams, and banks
- Banking customers: Group-IB’s recommendations for Android users are explicit. Do not click suspicious links received via email, SMS or social media; install applications only from official platforms such as Google Play Store; be suspicious of apps requesting excessive or unexpected permissions — including Accessibility Service permissions; and never enter banking PINs, mobile banking codes or card details into a screen that appeared unexpectedly.
- Security teams responsible for mobile defenses: RemControl’s use of a null VPN to suppress Google Play Protect and its creation of fresh signing keys in the Android Keystore are specific indicators to monitor. Teams should watch for installers that launch local VPN services, unexpected newly signed APKs on endpoints, WebView overlays mimicking legitimate apps, and inbound connections that route through Telegram‑based dead‑drops and WebSocket channels with JSON envelopes.
- Banks and fraud units: the payloads are tailored to capture institution-specific data (PINs, mobile banking codes, card expiry dates). Banks should be prepared for overlays that perfectly cover legitimate apps and for attackers who can capture screen content and UI element states — capabilities that complicate fraud-detection rules based solely on transaction characteristics.
Observed since July 2026 and already multilingual, RemControl’s architecture and exposed documentation make two concrete points: the platform is operational against at least 30 institutions in six countries, and its multilingual design suggests potential geographic expansion. The researchers’ inadvertent access to the trojan’s API documentation gave a rare, deep look at attacker tooling — and it also highlights a straightforward question left by the record: if operational details are publicly exposed once, will the operator alter infrastructure or tactics to close that visibility, and how quickly could those changes spread to the malware’s active campaigns?
Original reporting: https://www.infosecurity-magazine.com/news/banking-trojan-remote-control/




