Group-IB uncovers RemControl Android malware spreading via fake TVTap app
Group-IB researchers identified a new Android malware-as-a-service platform called RemControl, active since May and first sampled in July, that uses over 30 phishing overlays to steal banking credentials. The malware spreads via malvertising campaigns impersonating the TVTap IPTV app, using fake Google Play pages and Meta Pixel tracking, and targets users in Italy, France, Spain, Poland, Portugal, Canada, and parts of the Middle East.
GoKawiil's interpretation of the reporting above, not reported fact.
The use of an AI assistant response in one phishing overlay suggests the malware's creators leveraged AI tools to build parts of the operation, which could indicate a lower barrier to entry for producing convincing scams. Group-IB notes the VPN-blocking technique used to evade Google Play Protect has also appeared in ToxicPanda, a larger malware operation, suggesting shared tactics or tooling may be spreading across threat actors. This points to an evolving landscape where mobile banking malware increasingly blends ad-network abuse, fake app pages, and security-evasion techniques.
- RemControl is a new Android malware-as-a-service platform stealing banking credentials via fake app overlays.
- It spreads through malvertising impersonating the TVTap IPTV app and abuses Meta's ad ecosystem to reach victims.
- The malware evades Google Play Protect using a VPN-blocking technique also seen in the larger ToxicPanda malware campaign.
Bitdefender Mobile Security for Android — With banking malware like RemControl spreading through fake app pages and malvertising, having real-time mobile threat protection is essential. Bitdefender Mobile Security scans app installs and blocks phishing overlays before they can steal your banking credentials, adding a critical layer of defense beyond Google Play Protect.
See Bitdefender Mobile Security for Android on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-23
Published there as: “New RemControl Android banking malware targets users in Europe and Canada”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.