RemControl is an Android banking trojan operated as a malware-as-a-service platform and associated with the UNKK affiliate label. First observed in 2026, it targets retail-banking users in Italy, France, Spain, Poland, Portugal, Canada, and Gulf states, with phishing overlays covering more than 30 financial institutions. It is distributed through fraudulent Google Play-style landing pages impersonating a TV streaming application, including campaigns selectively serving Android users in targeted geographies and activity consistent with malvertising.
The installer presents a fake application-update interface, uses a local VPN service to interfere with Google Play Protect network activity, and creates a unique signing certificate for each installation. Payloads use obfuscation and, in newer variants, custom code packing. After installation, RemControl requests Android Accessibility Service permissions. It detects targeted banking applications and displays dynamically retrieved full-screen phishing overlays to capture banking PINs, mobile-banking codes, card-expiry information, and other credentials; the legitimate application may be restored after data submission to reduce suspicion.
Accessibility abuse enables RemControl to capture screenshots, collect active-window UI hierarchy data, log typed input and accessibility events, identify pattern-lock interactions, and execute remote taps, gestures, scrolling, and text injection. It can stream screen data to operators and attempts to impede removal by navigating users away from relevant system-settings pages. The malware obtains command-and-control locations through encrypted Telegram dead drops, allowing backend infrastructure and targeted applications to be changed without reinstalling the malware. A possible relationship to the Medusa affiliate UNKN has been noted, but remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Called RemControl, it hides behind fake download pages for a television streaming app, then waits for banking apps to open.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“Cover targeted banking apps with fake login screens to steal PINs, mobile banking codes and card expiry dates” and “Record clicks and typed text in all apps.”
“Cover targeted banking apps with fake login screens to steal PINs, mobile banking codes and card expiry dates” and “Record clicks and typed text in all apps.”
RemControl can log typed text and inspect a device's on-screen controls while streaming screenshots.
The malware fetches its server location through Telegram, allowing operators to change where infected phones connect without rebuilding the app.
“The fake pages arrive from an attacker-controlled server rather than being stored in the installed app. That lets operators change targets without asking victims to install another file.”
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan distributed through fake Google Play pages and malvertising. It abuses Accessibility Services to present fraudulent banking overlays, steal PINs and keystrokes, stream the victim screen, and enable full remote control. Its malware-as-a-service infrastructure uses Telegram dead-drops, affiliate tracking, and dynamic C2.
Android banking trojan delivered through fake streaming-app download pages. It uses remotely served full-screen banking overlays to steal PINs, banking codes, card details, and typed input; abuses Accessibility permissions for screen reading, screenshots, input automation, and remote device control; and uses Telegram as a dead-drop mechanism to update its server location.
Android banking trojan distributed through fake TV streaming-app download pages. It uses dynamically served full-screen banking overlays to capture PINs, banking codes, card data, and other credentials; abuses Accessibility permissions for screen reading, screenshots, input logging, and remote taps/swipes; and provides operators remote device control. It uses a VPN/local connection to interfere with Play Store traffic and security checks during installation, derives C2 location through Telegram dead drops, and can resist removal by disrupting Settings screens.
Android banking trojan distributed through fake TVTap IPTV download pages. Its dropper uses a VPN service to block Google Play Store traffic and evade Play Protect, then creates a per-device signing certificate to install the payload. With Accessibility permissions, RemControl overlays banking apps with credential-harvesting screens, captures screenshots, records input, supports remote device control, captures lock patterns, and inhibits removal. It retrieves encrypted C2 addresses from public Telegram channels and is offered as malware-as-a-service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.