Malware

RemControl: Android banking malware‑as‑a‑service leverages fake TVTap apps and VPN evasion

⏱️ 4 min read📅 9/24/2026👁️ 12 views

Why it matters

RemControl can silently steal banking PINs, codes, card details and even Android pattern‑lock coordinates, giving attackers full control over victims' financial accounts.

How the infection works

The campaign publishes counterfeit Google Play pages that masquerade as the popular TVTap IPTV application. Users who download the fake app unknowingly install the dropper.

Dropper and VPN evasion

Immediately after installation the dropper launches a VPN service that blocks all traffic to Google Play services. By cutting off Play Protect’s connectivity, the malware evades the store’s real‑time scanning.

Accessibility Service abuse

During setup the app requests Accessibility Service permission. Once granted it can draw full‑screen phishing overlays on top of legitimate banking apps, capturing PINs, banking codes, card expiry dates and credentials.

Real‑time control and UI harvesting

The operator receives live screenshots and the Android UI hierarchy, can record every tap, swipe, long‑press and injected text, and even issue remote gestures to complete fraudulent transactions.

Pattern‑lock theft

RemControl is capable of extracting pattern‑lock coordinates on a range of OEM devices, including Samsung, Xiaomi, Huawei, OPPO, OnePlus and stock Android builds.

Command‑and‑control

Encrypted C2 details are fetched from Telegram channels, allowing the infrastructure to be rotated on the fly. Researchers found an exposed FastAPI documentation page that listed the endpoints used to pull overlays and submit stolen data.

Who is at risk

The operation targets users in Europe—specifically Italy, France, Spain, Poland and Portugal—plus Canada and several Middle‑Eastern countries. Any Android device that installs the fake TVTap package and grants Accessibility Service permission is vulnerable.

Defensive steps

  • Only download apps from the official Google Play Store; double‑check the publisher’s name and app icon.
  • Do not grant Accessibility Service permission to apps that do not explicitly need it.
  • Keep Play Protect enabled and consider a mobile security solution that alerts on unknown VPN services.
  • Monitor network traffic for unexpected VPN tunnels or connections to Telegram‑based C2 hosts.
  • Prefer authentication methods that are resistant to overlay attacks, such as hardware‑based tokens.
  • Educate users to recognise phishing overlays that mimic banking interfaces.
#Android#Banking Trojan#RemControl#Accessibility Service#VPN evasion