Minacce · 7 ore fa
Group-IB ha trovato RemControl, un banking trojan Android distribuito tramite false pagine di download di TVTap, con vittime in oltre 30 banche tra Italia, Francia, Spagna, Polonia, Portogallo, Canada e alcuni Stati del Golfo. La novità non è solo il tema bancario: il malware entra da un canale che molti utenti considerano normale per un’app IPTV non presente sul Play Store.
Il falso installer chiede il permesso VPN e lo usa per bloccare il traffico del Play Store, così Play Protect non controlla l’app mentre si installa. Subito dopo chiede Accessibility, ottenendo controllo su ciò che appare sullo schermo e su ciò che viene digitato; da lì può sovrapporre schermate bancarie finte e rubare PIN e dati di carta.
Per chi supporta BYOD o clienti mobili, il punto è che la fiducia è stata spostata dal nome dell’app e dalle difese di Google alla richiesta di permessi e alla fonte di download. Chi installa IPTV da fonti non ufficiali entra così in una fascia di vittime concentrata e già pronta per il furto di credenziali bancarie.
3 fonti che coprono questa storia
RemControl Banking Trojan Gives Attackers Remote Control of Android De
The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials
New Android malware RemControl steals banking PINs and blocks removal attempts - Help Net Security
RemControl, a new Android banking trojan, spreads through a fake TVTap app, blocks Play Protect and steals PINs from bank customers.
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
Part of the PlainSec briefing for 2026-09-25