A new Android banking trojan, internally called RemControl, is quietly siphoning banking credentials from victims across Western Europe, the Middle East, and Canada while its own back-end infrastructure carries the fingerprints of an AI coding assistant that had no idea what it was building.
RemControl abuses Android’s Accessibility Service, the feature meant to help users with disabilities interact with their phones, to hijack banking apps from the inside.
It overlays fake login screens on top of legitimate banking apps, streams the victim’s screen in real time, logs every keystroke, and even reconstructs lock-screen patterns by mapping accessibility-tree coordinates across ten major Android skins, including Samsung One UI, MIUI, and ColorOS.
RemControl Android Banking Trojan
The malware spreads through counterfeit Google Play pages impersonating TVTap, a popular unofficial IPTV app that isn’t on the real Play Store, making users already comfortable downloading it from shady sources.

Group-IB traced six Italian-language distribution URLs that geofence delivery to Italian mobile IPs, backed by Meta Pixel tracking IDs suggesting the operator runs paid malvertising to funnel traffic.
Once installed, the dropper deploys a local VPN tunnel to silently blackhole Google Play Protect’s network traffic and generates a unique signing certificate per install, defeating both real-time scanning and hash-based detection. The most striking discovery came when Group-IB found RemControl’s C2 panel API documentation exposed online.
The backend, self-identified as “RemControl Proxy,” describes its credential-harvesting endpoints as handling “quiz answers” and frames the remote-control features as “parental-monitoring” tools. One panel document even labels a banking fraud victim as “a person staring at the quiz.”

The smoking gun: a test phishing overlay’s HTML file ends with complete, verbatim AI assistant response implementation notes, a summary of changes, and a closing offer to make further tweaks, accidentally left in a page actively served to bank customers.
Some overlays also contain Russian-language code comments, suggesting a Russian-speaking developer built at least part of the toolkit.
RemControl isn’t a one-off tool; it’s a full Malware-as-a-Service platform. Its exposed operator panel reveals a bot-management dashboard, an overlay template editor, a VNC-style session recorder with frame-by-frame replay, and a build system that generates custom APKs per affiliate, complete with configurable lure names, icons, and package identifiers.
Command-and-control resolution runs through an encrypted Telegram “dead-drop,” letting operators rotate infrastructure without ever recompiling the malware.
Group-IB tracks the threat actor behind the earliest campaigns as UNKK, based on hardcoded affiliate tags found in every sample, with campaign tags targeting Italy, France, Portugal, and Arabic-speaking markets.
Notably, droppers using identical naming conventions previously delivered the Medusa banking trojan under an affiliate tagged UNKN, just one letter removed from UNKK, raising the possibility, though not confirmed proof, of a shared operator lineage.
With overlays confirmed against more than 30 banks across six countries and multilingual support suggesting further expansion, Group-IB is urging financial institutions to deploy session-monitoring and digital-risk-protection tools, while advising users to avoid sideloaded apps and treat unexpected Accessibility Service permission requests as a red flag.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.