Protect.Computer
NEWS

RemControl: New Android Banking MaaS Hits Europe and Canada

· 1 min read · Malicious byte Device safety
RemControl: New Android Banking MaaS Hits Europe and Canada

Group-IB researchers have documented a new Android banking malware-as-a-service (MaaS) platform called RemControl, active since at least May 2026 and spreading through malvertising campaigns that impersonate the TVTap IPTV application. Victims land on fake Google Play pages — at least one Italian campaign used geofencing and mobile User-Agent checks to narrow targeting — and install a dropper that, once launched, immediately starts a VPN service to block all traffic to Google Play Services. Cutting off Play Protect before Accessibility permissions are requested is a technique also seen in ToxicPanda; here it gives RemControl a clean window to complete installation undetected.

Once Accessibility Services are granted, the malware can display full-screen phishing overlays on top of any of its 30+ targeted banking and financial apps, capturing PINs, card numbers, and login credentials in real time. It also streams screenshots and the full Android UI tree to operators, records every tap and keystroke, injects text remotely, and prevents uninstallation by detecting when users navigate to app-management or factory-reset settings and automatically exiting back to the home screen. C2 addresses are encrypted and hosted in Telegram channels, letting operators rotate infrastructure without redeploying the implant. Group-IB found an exposed FastAPI panel on one C2 proxy that revealed the endpoints used to push fresh banking overlays and collect harvested data. Targets so far span Italy, France, Spain, Poland, Portugal, Canada, and parts of the Middle East. One phishing overlay contains an AI assistant response, suggesting the malware was built with the help of AI coding tools.

How to check if you’re affected

Affected devices are any Android smartphones in the targeted regions that installed TVTap IPTV or a look-alike app from a site other than the official Google Play Store. To check: open Settings → Accessibility and look for any app that should not have that permission; revoke it immediately. Also open Settings → Apps and look for TVTap IPTV or any app you do not remember installing. If you find a suspicious entry, do a factory reset — Accessibility-capable malware can intercept uninstall attempts. Users who downloaded TVTap from an official, well-reviewed listing on the real Google Play Store are unlikely to be affected by this specific campaign.

Sources

Related reading