RemControl: New Android Banking Malware Leverages AI and Malvertising Campaigns
A new Android malware-as-a-service (MaaS) platform, dubbed **RemControl**, is actively targeting users in Europe, Canada, and the Middle East. Distributed via sophisticated malvertising campaigns impersonating the TVTap IPTV app, this banking trojan employs AI-generated phishing overlays and advanced evasion techniques to steal sensitive financial credentials.
.jpg)
**RemControl**, a novel Android malware-as-a-service (MaaS) platform, has emerged as a significant threat, primarily targeting financial credentials through elaborate malvertising campaigns. Researchers at cybersecurity firm **Group-IB** have been tracking its activity since at least May, with initial samples appearing in July.
### Sophisticated Distribution and Evasion
The malware's distribution leverages fake **Google Play** pages, meticulously designed to impersonate the legitimate **TVTap IPTV** application. Some campaigns, particularly in Italy, employ geofencing and mobile User-Agent checks to target specific victims. Notably, these malicious sites incorporate **Meta Pixel** tracking IDs, suggesting that operators may be abusing **Meta's** advertising ecosystem to funnel victims to their download pages.
Upon launch, **RemControl** initiates a VPN service. This clever tactic blocks traffic from **Google Play** services, effectively preventing **Play Protect** from performing real-time malware checks. This evasion technique has also been observed in recent versions of the **ToxicPanda** malware, indicating a growing trend among sophisticated Android threats.
### AI-Powered Phishing Overlays
**RemControl** stands out for its use of over 30 phishing overlays designed to mimic legitimate banking applications. One particularly alarming discovery by **Group-IB** researchers was an overlay displaying an AI assistant response, strongly indicating the malware's construction with the aid of AI models.


### Extensive Malicious Capabilities
During installation, **RemControl** aggressively requests Accessibility Service permissions. If granted, the malware gains extensive control over the device, enabling it to:
* Display full-screen phishing overlays to steal PINs, banking codes, card expiry dates, and other credentials.
* Dynamically receive new banking targets from its command-and-control (C2) infrastructure.
* Stream screenshots and the entire Android accessibility/UI tree to the operator in real-time.
* Record user input, including clicks, text changes, and focus events across applications.
* Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection.
* Capture Android pattern-lock coordinates across various OEMs, including **Samsung**, **Xiaomi**, **Huawei**, **OPPO**, **OnePlus**, and stock Android devices.
* Prevent removal by detecting attempts to access application-management, accessibility, or factory-reset settings and automatically exiting.

### C2 Infrastructure and Attribution
**RemControl** retrieves encrypted C2 information from **Telegram** channels, allowing for dynamic infrastructure rotation in case of disruptions. **Group-IB** also discovered exposed FastAPI documentation in the initial C2 proxy, revealing the endpoints used for fetching banking overlays and submitting stolen credentials.
While the origin of the threat actor remains unclear, the presence of Russian language in the HTML files of some overlays suggests a Russian-speaking developer. Based on a common identifier in analyzed samples, **Group-IB** tracks the **RemControl** operator as **UNKK** and suspects a connection to the **Medusa** banking trojan.
### Recommendations for Android Users
To mitigate the risk of **RemControl** and similar threats, Android users are strongly advised to:
* Avoid downloading APK files from sources outside of **Google Play** unless the publisher is explicitly trusted.
* Maintain regular **Play Protect** scans.
* Decline Accessibility Service permission requests from applications that do not genuinely require them for accessibility purposes.