RemControl Android banking MaaS (Group-IB 23 Sep): TVTap lure, Accessibility overlays, AI-built C2; EU/ME/Canada
Group-IB (published 23 September 2026) documents RemControl, a previously undocumented Android banking trojan sold as MaaS. Distribution uses fake Google Play pages impersonating the TVTap IPTV app (tvtap-hd[.]app / tvtap-liveapp[.]com, registered 10 Jul 2026; Italian campaigns geofence + User-Agent gate). The dropper starts a local VPN that null-routes com.android.vending to blunt Play Protect, then abuses Accessibility Service for full-screen banking overlays, UI-tree streaming, remote gestures, pattern-lock capture, and anti-removal. C2 is recovered from Telegram dead-drops (AES-128-CBC); early C2 bnbnhura[.]top registered 12 May 2026. Panel API docs and an overlay file that still contains a verbatim AI-assistant reply show AI-assisted build of backend and phishing HTML. Group-IB confirmed overlays for 30+ financial institutions across Western Europe, Middle East, and Canada (Italy/France primary). Affiliate tag UNKK; dropper naming overlaps prior Medusa/UNKN distribution. Wire: BleepingComputer.
- Product
- Android banking customers (RemControl MaaS / Accessibility overlay fraud)
- Versions
- n/a (malware; samples from ~Jul 2026; infra from May 2026)
- Exploited in Australia?
- unknown
- Patch to
- Block tvtap-hd[.]app, tvtap-liveapp[.]com, bnbnhura[.]top, definatelynoone[.]com; MDM: restrict sideload + Accessibility grants; hunt BIND_VPN_SERVICE droppers null-routing Play Store; user education against unofficial IPTV APKs; banks: monitor overlay/Fraud indicators for listed geos
Primary: Group-IB — RemControl: AI built the overlays (23 Sep 2026) · Vendor: Group-IB RemControl analysis · BleepingComputer — RemControl Android banking malware (23 Sep 2026)
