Researchers have detailed RemControl, an Android banking trojan that targets customers of more than 30 financial institutions across Europe, the Middle East, and Canada. The malware combines fake app-download pages, accessibility abuse, credential-stealing overlays, screen streaming, and remote-control capabilities.

How the campaign operates

Victims are lured to fraudulent pages impersonating an IPTV app. After installation and Accessibility Service approval, the malware can overlay targeted banking applications, collect credentials and one-time codes, and provide operators with visual and structured access to the device interface.

Detection and response

  • Warn users to install software only through trusted channels and scrutinize Accessibility prompts.
  • Monitor mobile telemetry for suspicious accessibility use, overlay behavior, and unusual network connections.
  • Use the reported, defanged indicators only in controlled threat-intelligence or security-monitoring workflows.

Source: GBHackers: RemControl Android banking malware, citing Group-IB research.

By Allan