malware
Published 2026-09-23
Verified 2026-09-27

RemControl Android banking MaaS (Group-IB 23 Sep): TVTap lure, Accessibility overlays, AI-built C2; EU/ME/Canada

Group-IB (published 23 September 2026) documents RemControl, a previously undocumented Android banking trojan sold as MaaS. Distribution uses fake Google Play pages impersonating the TVTap IPTV app (tvtap-hd[.]app / tvtap-liveapp[.]com, registered 10 Jul 2026; Italian campaigns geofence + User-Agent gate). The dropper starts a local VPN that null-routes com.android.vending to blunt Play Protect, then abuses Accessibility Service for full-screen banking overlays, UI-tree streaming, remote gestures, pattern-lock capture, and anti-removal. C2 is recovered from Telegram dead-drops (AES-128-CBC); early C2 bnbnhura[.]top registered 12 May 2026. Panel API docs and an overlay file that still contains a verbatim AI-assistant reply show AI-assisted build of backend and phishing HTML. Group-IB confirmed overlays for 30+ financial institutions across Western Europe, Middle East, and Canada (Italy/France primary). Affiliate tag UNKK; dropper naming overlaps prior Medusa/UNKN distribution. Wire: BleepingComputer.

Product
Android banking customers (RemControl MaaS / Accessibility overlay fraud)
Versions
n/a (malware; samples from ~Jul 2026; infra from May 2026)
Exploited in Australia?
unknown
Patch to
Block tvtap-hd[.]app, tvtap-liveapp[.]com, bnbnhura[.]top, definatelynoone[.]com; MDM: restrict sideload + Accessibility grants; hunt BIND_VPN_SERVICE droppers null-routing Play Store; user education against unofficial IPTV APKs; banks: monitor overlay/Fraud indicators for listed geos

Primary: Group-IB — RemControl: AI built the overlays (23 Sep 2026) · Vendor: Group-IB RemControl analysis · BleepingComputer — RemControl Android banking malware (23 Sep 2026)

tech identity ai