Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Android Banking Trojan Steals PINs with AI-Generated Overlays
September 24, 2026
Microsoft Unveils AI-Powered Security Copilot and SIEM for SOC Modernization
September 24, 2026
OpenAI Agent Did Not Hack Australian Medicare Portal, Vendor Clarifies
September 24, 2026
Home/Threats/New Android Banking Trojan Steals PINs with AI-Generated Overlays
Threats

New Android Banking Trojan Steals PINs with AI-Generated Overlays

Key Takeaways A new Android banking trojan, dubbed RemControl, is actively exploiting users by masquerading as a television streaming app. The malware utilizes AI-generated overlays to mimic...

Emy Elsamnoudy
Emy Elsamnoudy
September 24, 2026 5 Min Read
3 0

Key Takeaways

  • A new Android banking trojan, dubbed RemControl, is actively exploiting users by masquerading as a television streaming app.
  • The malware utilizes AI-generated overlays to mimic legitimate banking interfaces, stealing PINs and other sensitive financial data.
  • RemControl has targeted over 30 financial institutions across Europe, the Middle East, and Canada, with Italy and France being primary targets.
  • Beyond credential theft, the trojan gains extensive remote control capabilities, including screen monitoring, input recording, and bypassing security settings.
  • The campaign leverages sophisticated evasion techniques, such as geo-targeting, unique signing certificates for each installation, and using Telegram for command-and-control server updates.

Android Banking Trojan Leverages AI-Generated Overlays for PIN Theft

A sophisticated new Android banking trojan, identified as RemControl, is actively compromising users by posing as a legitimate television streaming application. This malware employs advanced techniques, including AI-generated graphical overlays, to deceptively capture banking Personal Identification Numbers (PINs) and other critical financial information from unsuspecting victims.

Table Of Content

  • Key Takeaways
  • Android Banking Trojan Leverages AI-Generated Overlays for PIN Theft
  • Widespread Targeting and Advanced Evasion
  • AI-Assisted Development and Dynamic Phishing
  • Installation and Persistent Control
  • What You Should Do

The attack vector typically begins with fake download pages that closely resemble official Google Play Store listings, despite the malicious streaming app not being available on the legitimate platform. In one observed campaign targeting Italian users, these deceptive pages were configured to deliver the malicious installer exclusively to Android devices with Italian IP addresses, effectively concealing the operation from broader scrutiny. Security researchers at Group-IB discovered RemControl, tracing its initial activity back to samples observed in July 2026.

Widespread Targeting and Advanced Evasion

According to Group-IB said in a report, the RemControl campaign has generated phishing screens designed to mimic the interfaces of more than 30 banking institutions across Europe, the Middle East, and Canada. While a precise victim count remains unconfirmed, Italy and France have been identified as the primary targets of this ongoing threat. The emergence of RemControl underscores a growing concern regarding the use of fake streaming app downloads as a conduit for deploying potent mobile malware.

RemControl’s capabilities extend far beyond simple credential harvesting. Once installed, it can monitor device screens, record user inputs, and grant attackers full remote control over the compromised device. This comprehensive control allows operators to manipulate the device, capture sensitive data, and bypass security measures, significantly elevating the risk to affected individuals.

AI-Assisted Development and Dynamic Phishing

A key distinguishing feature of RemControl is its apparent use of AI in its development. Investigators uncovered server documentation that bizarrely described stolen banking details as “quiz answers” and remote access functionalities as “parental monitoring.” Furthermore, a complete AI assistant response, including developmental notes and an offer for additional assistance, was found embedded within a live phishing page. These findings strongly suggest that an AI assistant was utilized to construct portions of the malicious platform, albeit under a misleading pretense of its intended purpose.

The malware operates by dynamically fetching fake banking interface pages from an attacker-controlled server. When a user opens a targeted banking application, RemControl overlays a full-screen replica of the bank’s login interface. Victims, believing they are interacting with their legitimate banking app, input their PINs, mobile banking codes, or card expiry dates into this imitation screen. Upon submission, the fake overlay disappears, and the genuine application reappears, leaving the user unaware that their credentials have been compromised. This server-side delivery mechanism allows threat actors to rapidly change their targets and update phishing screens without requiring victims to install new malware versions.

Installation and Persistent Control

The installation process for RemControl is designed to be deceptive and resilient. Initially, the dropper presents a fake streaming app update screen. It then requests VPN permissions, which it abuses to establish a local connection that blocks network traffic from the Google Play Store during installation. This tactic effectively circumvents real-time security checks that might otherwise detect and prevent the malware’s installation. To further complicate detection, each RemControl installation receives a newly generated signing certificate, making it difficult for security systems to identify the malware based on known file signatures.

Following installation, the trojan demands Android Accessibility access. This critical permission enables the malware to read screen content, capture screenshots, simulate user taps and swipes, and ultimately provide operators with complete remote control over the device. This abuse of Accessibility services mirrors techniques seen in other sophisticated banking malware campaigns, such as Perseus, which also leveraged fake streaming applications for distribution.

RemControl’s capabilities include logging all typed text, inspecting on-screen controls, and streaming real-time screenshots to its command-and-control server. It can also reconstruct unlock patterns and forcibly close settings screens when users attempt to remove the malware, ensuring persistence. These extensive features highlight that the threat extends beyond mere PIN theft, encompassing full device compromise and data exfiltration.

The operation appears to function as a service for other cybercriminals, evidenced by an exposed control panel offering tools for generating app builds, managing infected devices, and accessing stolen credentials. Investigators have linked observed samples to an affiliate identified as “UNKK,” though a definitive connection to other banking malware networks remains unproven.

The malware’s command-and-control server location is fetched via Telegram, allowing operators to dynamically update connection points without requiring app reinstallation. This flexibility, combined with updated overlays, enables the campaign to adapt quickly and target a broader range of financial institutions, aligning with a broader trend of banking PIN theft that combines deceptive screens with robust remote phone control capabilities.

What You Should Do

  • Avoid Side-Loading Apps: Only download applications from trusted sources like the official Google Play Store. Be highly suspicious of apps offered through direct links, unfamiliar websites, or third-party app stores.
  • Verify App Permissions: Carefully review all permission requests during app installation and after updates. Be particularly wary of requests for VPN services, Accessibility services, or permissions to install other apps from unknown sources, especially from apps that do not logically require them.
  • Be Skeptical of Unexpected Prompts: Never enter banking credentials or sensitive personal information into screens that appear unexpectedly or seem out of place within an application. If a banking app prompts for login details, close the app and reopen it to ensure it’s the legitimate interface.
  • Keep Software Updated: Ensure your Android operating system and all applications are kept up-to-date to benefit from the latest security patches.
  • Use a Reliable Mobile Security Solution: Install a reputable mobile antivirus or security suite that can detect and prevent malware infections.
  • Monitor Financial Accounts: Regularly check your bank statements and transaction history for any unauthorized activity.
  • Contact Your Bank Directly: If you suspect your account has been compromised or you’ve fallen victim to a phishing attempt, contact your bank immediately through official channels (e.g., the phone number on their official website or the back of your card), not through links or numbers provided in suspicious messages or apps.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps[:]//tvtap-hd[.]app/ Fake TVTap download website
URL hxxp[:]//vpn[.]doneplay[.]site/ Fake TVTap download website
URL hxxp[:]//ff-de[.]shutgpt[.]ir/ Fake TVTap download website
URL hxxp[:]//vpn[.]askarzadeh[.]com/ Fake TVTap download website
URL hxxp[:]//cdn[.]dlmafi[.]top/ Fake TVTap download website
URL hxxp[:]//216[.]126[.]229[.]216/ Fake TVTap download website
URL hxxps[:]//tvtap-liveapp[.]com/dl.php Final download URL
URL hxxps[:]//telegram[.]me/ftestera Telegram dead-drop
URL hxxps[:]//telegram[.]me/+Psyt04xu-cRjMTg0 Telegram dead-drop
Domain bnbnhura[.]top RemControl proxy server
URL hxxps[:]//definatelynoone[.]com Operator panel
URL hxxps[:]//157[.]90[.]179[.]116 Operator panel
Tracking ID 997470916598588 Meta Pixel ID embedded in distribution pages
Tracking ID 1909605966397328 Meta Pixel ID embedded in distribution pages
File name pattern instal*tvtap*.apk Dropper naming convention noted in the investigation
Configuration marker numeraZZZas Marker used to decode the server address
SHA-256 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b Dropper
SHA-256 fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e Dropper
SHA-256 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 Dropper
SHA-256 dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 Dropper
SHA-256 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb Dropper
SHA-256 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 Dropper
SHA-256 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d Dropper
SHA-256 cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 Dropper
SHA-256 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 Dropper
SHA-256 af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c Payload
SHA-256 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c Payload
SHA-256 c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 Payload
SHA-256 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f Payload
SHA-256 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a Payload
SHA-256 ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f Payload
SHA-256 b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 Payload
SHA-256 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 Payload
SHA-256 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 Payload

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Microsoft Unveils AI-Powered Security Copilot and SIEM for SOC Modernization

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Roundcube SQL Injection CVE-2023-43770 Exploited in Attacks
September 24, 2026
Malicious Firefox Extension Steals Google Account Sessions
September 24, 2026
Apache Tomcat Patches Critical WebSocket, HTTP/2 Vulnerabilities
September 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us