The dropper asks the victim for permission to install other apps | Image: Group-IB
At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | Operator tracked as UNKK |
| Activity Type | Android banking malware, credential theft, remote device control |
| Targets or Victims | Retail banking customers in Europe, Canada, and the Middle East |
| Scale | Targeted over 30 banking institutions; total victim count unconfirmed |
| Jurisdiction / Status | Unknown operator; uncharged |
| Source | Group-IB Threat Intelligence |
TL;DR
Cybersecurity researchers identified the RemControl Android banking trojan targeting mobile users. The malware uses a fake TVTap app to infect devices and steal banking PINs. It blocks Google Play Protect and grants attackers full remote control over infected phones.
What Happened
Threat actors are distributing a new Android banking trojan called RemControl. They buy malicious advertisements on Meta platforms to lure victims. These ads direct users to fake Google Play Store pages. The fraudulent pages offer a free download of TVTap. TVTap is a popular third-party IPTV streaming application. The threat actors use geofencing and mobile User-Agent checks. They only serve the malicious application to specific targets. For example, one campaign specifically targeted Italian IP addresses.
Who Is Behind It
Group-IB researchers track the RemControl operator under the identifier UNKK. Researchers suspect a potential connection to the older Medusa banking trojan. Analysts found Russian language artifacts within the HTML files of some overlays. This indicates a Russian speaker likely developed parts of the code. The operator’s true identity remains unknown. Law enforcement has not announced any charges against the developer. The threat actor runs this operation as a Malware-as-a-Service platform.
Impact and Scale
The RemControl Android banking trojan targets customers of over 30 banking institutions. These financial targets span across Italy, France, Spain, Poland, Portugal, Canada, and the Middle East. The malware uses Android Accessibility Services to achieve full device control. It displays fake phishing overlays on top of legitimate banking apps. The trojan captures banking PINs, card expiry dates, and login credentials. It can stream the device screen in real time to the operator. It also captures Android pattern-lock coordinates across multiple device manufacturers. The malware establishes command-and-control channels using encrypted Telegram dead-drops. Interestingly, developers left a verbatim artificial intelligence assistant response inside one phishing overlay. This proves the creator used artificial intelligence models to write the code.
What Comes Next
The malware blocks removal attempts to ensure persistence. The dropper starts a virtual private network service that blocks traffic to Google Play services. This prevents Play Protect from performing real-time security checks. The malware also automatically closes application management and factory reset menus. Users should avoid downloading applications from outside the official Google Play Store. Mobile device management solutions can help block unauthorized application installations on corporate devices.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!