Download Privacy Needle App

Type to search

Cybersecurity

RemControl Android Trojan Uses Accessibility Services to Steal Banking Credentials

Share

Group-IB researchers have discovered a new Android banking trojan named RemControl that has been targeting retail banking customers across Canada, the Middle East, and Western Europe since July 2026.

The malware has been observed targeting more than 30 banking institutions across six countries. It leverages the Android Accessibility Service to gain full remote control over victim devices and extract sensitive financial credentials.

AI-Assisted Infrastructure and Evasion

The malware developer, a Russian-speaking operator tracked as UNKK, appears to have used an AI assistant to build significant portions of the command and control (C2) backend and phishing overlays. Researchers believe the developer may have tricked the AI model into generating the code by presenting the API endpoints as components for a parental monitoring application.

RemControl is typically distributed through fraudulent Google Play Store pages that impersonate the TVTap IPTV application. These pages are personalised using IP geolocation and user-agent data to match the visitor’s local language.

To evade detection, the trojan employs several sophisticated techniques. It launches a local VPN service to route traffic from Google Play Protect through a null channel, effectively suppressing the built-in Android security tool. Additionally, the dropper generates a new signing key in the Android Keystore to sign the RemControl payload, which helps it bypass hash-based detection.

Device Control and Data Theft

Once the Accessibility Service permission is granted, RemControl can capture the device screen, provide a machine-readable map of the user interface, and perform keylogging. This allows the attacker to track user activity, including clicks, selection changes, and unlock patterns.

The trojan also uses full-screen WebView overlays to impersonate legitimate banking applications. These overlays are designed to collect PIN codes, mobile banking codes, and card expiry dates. To maintain access, the malware includes self-preservation functions that can prevent application removal and block factory reset screens.

Stolen data is exfiltrated through a Telegram dead-drop mechanism and a WebSocket channel using JSON envelopes.

Mitigation Strategies

To reduce the risk of infection, security researchers recommend the following actions:

  • Avoid clicking on suspicious links received via email, SMS, or social media.
  • Install applications only from official platforms such as the Google Play Store.
  • Be wary of any application that requests excessive or unexpected permissions, particularly Accessibility Services.
  • Never enter banking PINs, mobile banking codes, or card details into an unexpected or suspicious screen.
Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.