A newly-discovered Android banking trojan abuses Accessibility Services to gain remote control over victim’s devices and collect credentials including PIN codes, mobile banking codes and card expiry dates, Group-IB researchers have warned.
The trojan, named RemControl by its operator, has been observed targeting retail banking customers across Western Europe, the Middle East and Canada since July 2026.
“With confirmed targeting of more than 30 banking institutions across six countries, it represents a serious threat to both banks and their customers,” the Group-IB researchers said.
The malware is able to support multiple languages, which suggests RemControl may expand its activities to other regions in the future.
AI Assistant Manipulated to Build Malware
The malware developer, believed to be Russian-speaking operator tracked as UNKK, appears to have used an AI assistant to build significant portions of the command and control (C2) backend and phishing overlays.
The developer is likely to have tricked the AI model into thinking that the API endpoints it created was for a parental monitoring app.
“The result is a functional banking fraud platform whose own documentation describes credential theft as quiz completion and banking victims as ‘a person staring at the quiz,’” Group-IB wrote in a blog post dated September 23.
RemControl’s C2 panel’s API documentation was inadvertently exposed during the Group-IB analysis, allowing the researchers to gain deep insights into the trojan’s infrastructure.
How RemControl Controls Victim Devices
Victims are lured into downloading RemControl through fake Google Play Store pages impersonating the TVTap IPTV application.
These pages are adapted to local languages, based on the visitor’s user-agent and IP geolocation.
After downloading the application, the victim is presented with a WebView-based UI impersonating a TVTap update screen. If they click “install”, a dropper performs a series of actions to block detection and install the RemControl malware.
This includes launching a local VPN service that routes traffic from Google Play Protect through a null VPN channel. Google Play Protect is an in-built malware defense tool for Android devices.
“VPN-based Play Protect suppression is becoming a recurring pattern in Android dropper development, reflecting a broader awareness of mobile security mechanisms among Android malware developers,” the researchers noted.
The dropper also generates a fresh signing key in the Android Keystore and uses it to sign the RemControl payload before installation to evade hash-based detection.
Once the trojan is installed, the payload immediately requests Accessibility Service permissions from the victim, which if granted, provides RemControl full control over the device.
The Android Accessibility Service is a background application that enhances the user interface to help people with disabilities or temporary impairments interact with their devices.
At this stage, RemControl can perform a range of functions designed to capture sensitive banking information from the victim.
This includes inflating a full-screen WebView overlay, which collects credentials such as PIN codes, mobile banking codes and card expiry dates depending on the targeted institution.
The overlay covers the legitimate banking application entirely from the victim’s point of view.
RemControl can also abuse the accessibility service to capture the device screen, giving the operator a machine-readable map of every visible UI element including coordinates, text content and interactive state.
In addition, the trojan can capture keylogging and pattern lock, allowing the attacker to track user activity such as clicks, selection changes and unlock pattern.
RemControl also has a self-preservation function to maintain persistent access to the victim’s device. It is able to prevent application removal and factory reset screens.
Captured data is sent through a Telegram dead-drop mechanism, hiding the real C2 address behind an additional layer. The primary channel is a WebSocket, with messages using a JSON envelope with fields cmd, udid, rid and data.
Banking Customers Urged to Stay Vigilant
Group-IB set out recommendations for banking customers using Android devices to avoid falling victim to the RemControl trojan. These include:
- Do not click on suspicious links received via email, SMS or social media
- Only install applications from official platforms such as Google Play Store
- Be suspicious of apps requesting excessive or unexpected permissions, including Accessibility Service permissions
- Never enter your banking PIN, mobile banking code or card details into a screen that appeared unexpectedly










![Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ/s1700-nu-rw-lo-l85-e365/third.jpg)