Cybersecurity company Group-IB identified a new malware-as-a-service platform called RemControl, targeting Android device users through malicious advertising campaigns impersonating the TVTap IPTV app. The platform uses fake download pages resembling Google Play to persuade victims to install the malicious app.
The threat-related infrastructure has been active since at least May 2026, while the first samples appeared in July. The samples contained more than 30 phishing interfaces designed to steal banking credentials. Targeted countries include Italy, France, Spain, Poland, Portugal, and Canada, in addition to countries in the Middle East.
How Does RemControl Reach Devices?
The malware spreads through fake websites impersonating Google Play pages for the TVTap IPTV app. Group-IB observed an Italian campaign that used geolocation and checks of the phone's User-Agent information to direct specific users to the download page. The websites also contained Meta Pixel tracking identifiers, suggesting the abuse of Meta's advertising ecosystem to attract victims to the malicious pages.
After the dropper runs, the malware starts a VPN service that blocks traffic from Google Play services, which may prevent Play Protect from performing real-time scans for known malware. RemControl asked users to grant it Accessibility Service permission, which allows it to perform a large part of its monitoring and control operations.
Data Theft and Control Capabilities
- Displaying full phishing interfaces over legitimate banking applications and stealing PINs, banking service codes, card expiration dates, and login credentials.
- Dynamically receiving new banking targets from command-and-control servers.
- Streaming screenshots and the Android user interface tree, with real-time access to the operator.
- Recording taps, text changes, focus events, and user input within applications.
- Performing taps, scrolling, gestures, long presses, and remote text injection.
- Capturing screen-lock pattern coordinates on devices from Samsung, Xiaomi, Huawei, OPPO, and OnePlus, in addition to standard Android devices.
- Resisting removal by detecting when the victim enters application-management settings, Accessibility settings, or the factory-reset process, then exiting automatically.
Why Does This Matter?
RemControl's danger is not limited to stealing static credentials; abusing Accessibility permissions gives the operator interactive capability to monitor the device interface and perform actions within applications. The ability to update banking targets remotely also makes the platform adaptable to new services, instead of relying on a fixed list within the sample.
The malware extracted encrypted command-and-control server information from Telegram channels, allowing the infrastructure to be changed when it is disrupted. Exposed FastAPI documentation in the initial control-server agent also revealed the endpoints used to retrieve phishing interfaces and send stolen credentials. The identity of the operating group remains unresolved, but the presence of Russian language in HTML files for some interfaces indicates that a Russian-speaking developer participated in developing some of them. Group-IB tracks the operator under the name UNKK and suspects a connection to the Medusa banking trojan, although the source has not definitively established this connection.
What Should Android Users Do?
Group-IB recommends avoiding the download of APK files from outside Google Play unless their publisher is clearly trusted, and conducting regular Play Protect scans. Users should also reject Accessibility Service permission requests from applications that do not genuinely need it for accessibility purposes, because granting it to entertainment or unknown applications may enable input monitoring and device control.