Malware & Tooling · Credential Theft

RemControl Uses Fake TVTap to Disarm Android Safety Checks

Group-IB found a new Android banking trojan, RemControl, being spread through fake TVTap IPTV download pages and used against customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada, and Gulf states. The first samples were submitted to VirusTotal on July 19, 2026, and the operator tags in the campaign point to UNKK.

The fake installer asks for VPN permission, then uses that VPN to block Google Play Store traffic so Play Protect cannot inspect the app while it installs. It then asks for Accessibility access, which lets the malware overlay fake banking screens, capture PINs and card details, and record what users type or tap.

For Android teams, the exposure sits in the sideload-and-prompt path, not just on the device. If users already trust unofficial IPTV downloads or approve VPN and Accessibility prompts, Google’s own safety checks can be pushed out of the loop before the trojan reaches a bank app.

2 sources · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-24

Every edition of this story: RemControl Uses Fake TVTap to Disarm Android Safety Checks

More from today