A new Android banking trojan called RemControl is using fake streaming app downloads to target people’s banking information.
The malware hides behind websites that look like Google Play pages. However, the streaming app being promoted is not actually available on Google Play.
In one campaign targeting Italy, the malicious download was shown only to Android users with Italian IP addresses. Researchers from Group-IB identified RemControl in samples dating back to July 2026.
More than 30 banking institutions across Europe, the Middle East, and Canada were found to have matching fake login screens. Italy and France were among the main targets observed, although the exact number of victims is not known.
RemControl is not limited to stealing banking details. It can also monitor the device screen, record user input, and give attackers remote control.
Fake Banking Screens Trick Users
When a targeted banking app is opened, RemControl displays a fake version of the bank’s screen on top of the real application.
The victim may enter sensitive information such as:
- Banking PINs
- Mobile banking codes
- Card expiry details
- Other login information
After the information is submitted, the fake screen disappears and the legitimate banking app appears again.
The fake screens are downloaded from an attacker-controlled server instead of being permanently stored inside the malware. This allows criminals to change the targeted banks without requiring victims to install another application.
Researchers also found signs that an AI assistant may have been used during the development of parts of the criminal platform. However, the malware itself does not appear to use AI on the infected device.
Fake Streaming App Leads to Remote Control
The infection begins with a fake streaming app update page. During installation, the malware can request VPN access and interfere with network traffic from the Play Store.
After installation, RemControl asks the victim to enable Android Accessibility permissions.
With these permissions, the malware can:
- Read information displayed on the screen
- Take screenshots
- Perform taps and swipes
- Record typed text
- Monitor on-screen controls
- Interfere with attempts to remove the malware
This gives attackers much more control than simply stealing a banking PIN.
Users Should Be Careful With App Downloads
RemControl can obtain its command-and-control address through Telegram, allowing attackers to change the server used by infected devices.
The operation also includes a control panel that can help manage infected devices, create malware builds, and view stolen information.
Android users should avoid downloading apps through unfamiliar websites or links, even when the page looks like an official Google Play listing.
Be especially careful if an app unexpectedly asks for VPN or Accessibility permissions. Never enter banking information into a screen that appears unexpectedly.
If you suspect your banking information has been exposed, contact your bank through its official channels immediately.
IoCs
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[:]//tvtap-hd[.]app/ | Fake TVTap download website |
| URL | hxxp[:]//vpn[.]doneplay[.]site/ | Fake TVTap download website |
| URL | hxxp[:]//ff-de[.]shutgpt[.]ir/ | Fake TVTap download website |
| URL | hxxp[:]//vpn[.]askarzadeh[.]com/ | Fake TVTap download website |
| URL | hxxp[:]//cdn[.]dlmafi[.]top/ | Fake TVTap download website |
| URL | hxxp[:]//216[.]126[.]229[.]216/ | Fake TVTap download website |
| URL | hxxps[:]//tvtap-liveapp[.]com/dl.php | Final download URL |
| URL | hxxps[:]//telegram[.]me/ftestera | Telegram dead-drop |
| URL | hxxps[:]//telegram[.]me/+Psyt04xu-cRjMTg0 | Telegram dead-drop |
| Domain | bnbnhura[.]top | RemControl proxy server |
| URL | hxxps[:]//definatelynoone[.]com | Operator panel |
| URL | hxxps[:]//157[.]90[.]179[.]116 | Operator panel |
| Tracking ID | 997470916598588 | Meta Pixel ID embedded in distribution pages |
| Tracking ID | 1909605966397328 | Meta Pixel ID embedded in distribution pages |
| File name pattern | instal*tvtap*.apk | Dropper naming convention noted in the investigation |
| Configuration marker | numeraZZZas | Marker used to decode the server address |
| SHA-256 | 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b | Dropper |
| SHA-256 | fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e | Dropper |
| SHA-256 | 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 | Dropper |
| SHA-256 | dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 | Dropper |
| SHA-256 | 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb | Dropper |
| SHA-256 | 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 | Dropper |
| SHA-256 | 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d | Dropper |
| SHA-256 | cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 | Dropper |
| SHA-256 | 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 | Dropper |
| SHA-256 | af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c | Payload |
| SHA-256 | 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c | Payload |
| SHA-256 | c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 | Payload |
| SHA-256 | 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f | Payload |
| SHA-256 | 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a | Payload |
| SHA-256 | ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f | Payload |
| SHA-256 | b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 | Payload |
| SHA-256 | 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 | Payload |
| SHA-256 | 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 | Payload |