Remo is an Android remote access trojan used in mobile banking fraud campaigns. The provided content links it to GoldFactory, a financially motivated Chinese-speaking cybercrime group targeting users in Indonesia, Thailand, and Vietnam since at least October 2024. In these campaigns, attackers impersonate government services and use phone calls, messaging apps, and fake Google Play Store landing pages to trick victims into installing trojanized or modified banking applications. Remo is described as being deployed alongside other Android RATs such as Gigabud and MMRat.
High-confidence reporting in the content also identifies Remo as Android.BankBot.Remo.1.origin and states that it abuses Android Accessibility Services to steal data from banking applications and cryptocurrency wallets. The broader GoldFactory tradecraft described in the content indicates that malware in this campaign is injected into legitimate banking apps while preserving normal app functionality, and uses runtime-hooking frameworks such as Frida, Dobby, and Pine to bypass security controls and conceal malicious behavior. Reported capabilities associated with these modified-app campaigns include remote control via accessibility abuse, hiding accessibility-enabled apps, preventing screencast detection, spoofing app signatures, hiding installation sources, implementing custom integrity tokens, and obtaining account balances.
The content does not provide specific standalone indicators of compromise for Remo such as hashes, package names, domains, or C2 infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan leveraging Accessibility Services to steal data from banking apps and crypto wallets; observed in parts of Southeast Asia/APAC.
Banking trojan leveraging Android Accessibility Services to steal data from banking apps and crypto wallets; observed targeting Southeast Asia/APAC users.
A remote access trojan for Android, distributed via fake banking apps, used for remote control and credential theft.
Android remote access trojan used for remote control and fraud, distributed through impersonation of legitimate services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.