Malware · 5h ago
Group-IB found a new Android banking trojan, RemControl, being spread through fake TVTap IPTV download pages and used against customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada, and Gulf states. The first samples were submitted to VirusTotal on July 19, 2026, and the operator tags in the campaign point to UNKK.
The fake installer asks for VPN permission, then uses that VPN to block Google Play Store traffic so Play Protect cannot inspect the app while it installs. It then asks for Accessibility access, which lets the malware overlay fake banking screens, capture PINs and card details, and record what users type or tap.
For Android teams, the exposure sits in the sideload-and-prompt path, not just on the device. If users already trust unofficial IPTV downloads or approve VPN and Accessibility prompts, Google’s own safety checks can be pushed out of the loop before the trojan reaches a bank app.
2 sources covering this story
New Android malware RemControl steals banking PINs and blocks removal attempts - Help Net Security
RemControl, a new Android banking trojan, spreads through a fake TVTap app, blocks Play Protect and steals PINs from bank customers.
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
Part of the PlainSec briefing for 2026-09-24