UNKK is the affiliate label associated with observed RemControl Android banking-trojan campaigns. RemControl is operated as a malware-as-a-service platform targeting retail-banking customers, with confirmed phishing overlays for more than 30 financial institutions. Observed activity principally targeted Italy and France, with additional targeting of banks in Spain, Poland, Portugal, Canada, and Gulf states. The operation distributes malicious Android applications through counterfeit Google Play-style pages impersonating a TVTap IPTV application, including geographically selective delivery. RemControl abuses Android Accessibility Service permissions to present dynamically retrieved banking overlays, capture banking PINs, authentication codes, card-expiry data, typed input, screenshots, and UI hierarchy data. It supports remote interaction with infected devices, including taps, gestures, scrolling, and text injection, and collects information usable for Android unlock-pattern reconstruction. The malware employs evasion measures including interference with Play Protect network traffic during installation, per-installation signing certificates, code obfuscation and packing, Telegram-based dead-drop C2 discovery, and resistance to removal through navigation away from relevant Android settings. Exposed management functionality included per-affiliate application building, infected-device management, overlay editing, credential viewing, automation, and remote-session capabilities. Similarities with the Medusa banking-malware affiliate UNKN have been reported, but no definitive relationship between UNKK and UNKN has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An affiliate-associated Android banking-trojan operation distributing RemControl through fake streaming-app download pages. It targets banking customers with remotely served banking-app overlays and remote device-control capabilities to capture PINs, banking codes, card data, and other credentials.
An affiliate associated with the RemControl Android banking-trojan operation, which distributes malicious APKs through fake streaming-app download pages and steals banking credentials through dynamically delivered overlays and remote device control.
Operates the RemControl Android banking trojan as malware-as-a-service, distributing it through fake Google Play pages impersonating TVTap IPTV and targeting banking customers.
Operator of the RemControl Android banking-trojan MaaS platform, conducting parallel campaigns against retail-banking users. It uses fake Google Play pages impersonating TVTap, malvertising, Accessibility Service abuse, banking overlays, real-time screen streaming, keylogging, remote device control, and Telegram dead-drops for C2 resolution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.