Why it matters
RemControl can silently steal banking PINs, codes, card details and even Android pattern‑lock coordinates, giving attackers full control over victims' financial accounts.
How the infection works
The campaign publishes counterfeit Google Play pages that masquerade as the popular TVTap IPTV application. Users who download the fake app unknowingly install the dropper.
Dropper and VPN evasion
Immediately after installation the dropper launches a VPN service that blocks all traffic to Google Play services. By cutting off Play Protect’s connectivity, the malware evades the store’s real‑time scanning.
Accessibility Service abuse
During setup the app requests Accessibility Service permission. Once granted it can draw full‑screen phishing overlays on top of legitimate banking apps, capturing PINs, banking codes, card expiry dates and credentials.
Real‑time control and UI harvesting
The operator receives live screenshots and the Android UI hierarchy, can record every tap, swipe, long‑press and injected text, and even issue remote gestures to complete fraudulent transactions.
Pattern‑lock theft
RemControl is capable of extracting pattern‑lock coordinates on a range of OEM devices, including Samsung, Xiaomi, Huawei, OPPO, OnePlus and stock Android builds.
Command‑and‑control
Encrypted C2 details are fetched from Telegram channels, allowing the infrastructure to be rotated on the fly. Researchers found an exposed FastAPI documentation page that listed the endpoints used to pull overlays and submit stolen data.
Who is at risk
The operation targets users in Europe—specifically Italy, France, Spain, Poland and Portugal—plus Canada and several Middle‑Eastern countries. Any Android device that installs the fake TVTap package and grants Accessibility Service permission is vulnerable.
Defensive steps
- Only download apps from the official Google Play Store; double‑check the publisher’s name and app icon.
- Do not grant Accessibility Service permission to apps that do not explicitly need it.
- Keep Play Protect enabled and consider a mobile security solution that alerts on unknown VPN services.
- Monitor network traffic for unexpected VPN tunnels or connections to Telegram‑based C2 hosts.
- Prefer authentication methods that are resistant to overlay attacks, such as hardware‑based tokens.
- Educate users to recognise phishing overlays that mimic banking interfaces.