New Android Banking Trojan Steals PINs with AI-Generated Overlays
Key Takeaways A new Android banking trojan, dubbed RemControl, is actively exploiting users by masquerading as a television streaming app. The malware utilizes AI-generated overlays to mimic...
Key Takeaways
- A new Android banking trojan, dubbed RemControl, is actively exploiting users by masquerading as a television streaming app.
- The malware utilizes AI-generated overlays to mimic legitimate banking interfaces, stealing PINs and other sensitive financial data.
- RemControl has targeted over 30 financial institutions across Europe, the Middle East, and Canada, with Italy and France being primary targets.
- Beyond credential theft, the trojan gains extensive remote control capabilities, including screen monitoring, input recording, and bypassing security settings.
- The campaign leverages sophisticated evasion techniques, such as geo-targeting, unique signing certificates for each installation, and using Telegram for command-and-control server updates.
Android Banking Trojan Leverages AI-Generated Overlays for PIN Theft
A sophisticated new Android banking trojan, identified as RemControl, is actively compromising users by posing as a legitimate television streaming application. This malware employs advanced techniques, including AI-generated graphical overlays, to deceptively capture banking Personal Identification Numbers (PINs) and other critical financial information from unsuspecting victims.
Table Of Content
The attack vector typically begins with fake download pages that closely resemble official Google Play Store listings, despite the malicious streaming app not being available on the legitimate platform. In one observed campaign targeting Italian users, these deceptive pages were configured to deliver the malicious installer exclusively to Android devices with Italian IP addresses, effectively concealing the operation from broader scrutiny. Security researchers at Group-IB discovered RemControl, tracing its initial activity back to samples observed in July 2026.
Widespread Targeting and Advanced Evasion
According to Group-IB said in a report, the RemControl campaign has generated phishing screens designed to mimic the interfaces of more than 30 banking institutions across Europe, the Middle East, and Canada. While a precise victim count remains unconfirmed, Italy and France have been identified as the primary targets of this ongoing threat. The emergence of RemControl underscores a growing concern regarding the use of fake streaming app downloads as a conduit for deploying potent mobile malware.
RemControl’s capabilities extend far beyond simple credential harvesting. Once installed, it can monitor device screens, record user inputs, and grant attackers full remote control over the compromised device. This comprehensive control allows operators to manipulate the device, capture sensitive data, and bypass security measures, significantly elevating the risk to affected individuals.
AI-Assisted Development and Dynamic Phishing
A key distinguishing feature of RemControl is its apparent use of AI in its development. Investigators uncovered server documentation that bizarrely described stolen banking details as “quiz answers” and remote access functionalities as “parental monitoring.” Furthermore, a complete AI assistant response, including developmental notes and an offer for additional assistance, was found embedded within a live phishing page. These findings strongly suggest that an AI assistant was utilized to construct portions of the malicious platform, albeit under a misleading pretense of its intended purpose.
The malware operates by dynamically fetching fake banking interface pages from an attacker-controlled server. When a user opens a targeted banking application, RemControl overlays a full-screen replica of the bank’s login interface. Victims, believing they are interacting with their legitimate banking app, input their PINs, mobile banking codes, or card expiry dates into this imitation screen. Upon submission, the fake overlay disappears, and the genuine application reappears, leaving the user unaware that their credentials have been compromised. This server-side delivery mechanism allows threat actors to rapidly change their targets and update phishing screens without requiring victims to install new malware versions.
Installation and Persistent Control
The installation process for RemControl is designed to be deceptive and resilient. Initially, the dropper presents a fake streaming app update screen. It then requests VPN permissions, which it abuses to establish a local connection that blocks network traffic from the Google Play Store during installation. This tactic effectively circumvents real-time security checks that might otherwise detect and prevent the malware’s installation. To further complicate detection, each RemControl installation receives a newly generated signing certificate, making it difficult for security systems to identify the malware based on known file signatures.
Following installation, the trojan demands Android Accessibility access. This critical permission enables the malware to read screen content, capture screenshots, simulate user taps and swipes, and ultimately provide operators with complete remote control over the device. This abuse of Accessibility services mirrors techniques seen in other sophisticated banking malware campaigns, such as Perseus, which also leveraged fake streaming applications for distribution.
RemControl’s capabilities include logging all typed text, inspecting on-screen controls, and streaming real-time screenshots to its command-and-control server. It can also reconstruct unlock patterns and forcibly close settings screens when users attempt to remove the malware, ensuring persistence. These extensive features highlight that the threat extends beyond mere PIN theft, encompassing full device compromise and data exfiltration.
The operation appears to function as a service for other cybercriminals, evidenced by an exposed control panel offering tools for generating app builds, managing infected devices, and accessing stolen credentials. Investigators have linked observed samples to an affiliate identified as “UNKK,” though a definitive connection to other banking malware networks remains unproven.
The malware’s command-and-control server location is fetched via Telegram, allowing operators to dynamically update connection points without requiring app reinstallation. This flexibility, combined with updated overlays, enables the campaign to adapt quickly and target a broader range of financial institutions, aligning with a broader trend of banking PIN theft that combines deceptive screens with robust remote phone control capabilities.
What You Should Do
- Avoid Side-Loading Apps: Only download applications from trusted sources like the official Google Play Store. Be highly suspicious of apps offered through direct links, unfamiliar websites, or third-party app stores.
- Verify App Permissions: Carefully review all permission requests during app installation and after updates. Be particularly wary of requests for VPN services, Accessibility services, or permissions to install other apps from unknown sources, especially from apps that do not logically require them.
- Be Skeptical of Unexpected Prompts: Never enter banking credentials or sensitive personal information into screens that appear unexpectedly or seem out of place within an application. If a banking app prompts for login details, close the app and reopen it to ensure it’s the legitimate interface.
- Keep Software Updated: Ensure your Android operating system and all applications are kept up-to-date to benefit from the latest security patches.
- Use a Reliable Mobile Security Solution: Install a reputable mobile antivirus or security suite that can detect and prevent malware infections.
- Monitor Financial Accounts: Regularly check your bank statements and transaction history for any unauthorized activity.
- Contact Your Bank Directly: If you suspect your account has been compromised or you’ve fallen victim to a phishing attempt, contact your bank immediately through official channels (e.g., the phone number on their official website or the back of your card), not through links or numbers provided in suspicious messages or apps.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[:]//tvtap-hd[.]app/ |
Fake TVTap download website |
| URL | hxxp[:]//vpn[.]doneplay[.]site/ |
Fake TVTap download website |
| URL | hxxp[:]//ff-de[.]shutgpt[.]ir/ |
Fake TVTap download website |
| URL | hxxp[:]//vpn[.]askarzadeh[.]com/ |
Fake TVTap download website |
| URL | hxxp[:]//cdn[.]dlmafi[.]top/ |
Fake TVTap download website |
| URL | hxxp[:]//216[.]126[.]229[.]216/ |
Fake TVTap download website |
| URL | hxxps[:]//tvtap-liveapp[.]com/dl.php |
Final download URL |
| URL | hxxps[:]//telegram[.]me/ftestera |
Telegram dead-drop |
| URL | hxxps[:]//telegram[.]me/+Psyt04xu-cRjMTg0 |
Telegram dead-drop |
| Domain | bnbnhura[.]top |
RemControl proxy server |
| URL | hxxps[:]//definatelynoone[.]com |
Operator panel |
| URL | hxxps[:]//157[.]90[.]179[.]116 |
Operator panel |
| Tracking ID | 997470916598588 |
Meta Pixel ID embedded in distribution pages |
| Tracking ID | 1909605966397328 |
Meta Pixel ID embedded in distribution pages |
| File name pattern | instal*tvtap*.apk |
Dropper naming convention noted in the investigation |
| Configuration marker | numeraZZZas |
Marker used to decode the server address |
| SHA-256 | 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b |
Dropper |
| SHA-256 | fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e |
Dropper |
| SHA-256 | 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 |
Dropper |
| SHA-256 | dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 |
Dropper |
| SHA-256 | 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb |
Dropper |
| SHA-256 | 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 |
Dropper |
| SHA-256 | 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d |
Dropper |
| SHA-256 | cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 |
Dropper |
| SHA-256 | 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 |
Dropper |
| SHA-256 | af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c |
Payload |
| SHA-256 | 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c |
Payload |
| SHA-256 | c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 |
Payload |
| SHA-256 | 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f |
Payload |
| SHA-256 | 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a |
Payload |
| SHA-256 | ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f |
Payload |
| SHA-256 | b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 |
Payload |
| SHA-256 | 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 |
Payload |
| SHA-256 | 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 |
Payload |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.