Group-IB identified RemControl, an Android banking trojan distributed through counterfeit Google Play-style pages impersonating the TVTap IPTV app. The campaign selectively delivered malicious installers to Android devices using Italian IP addresses and primarily targeted users in Italy and France, while its overlays impersonated more than 30 financial institutions across Europe, the Middle East, Canada, and Gulf states. The dynamically server-hosted screens capture banking PINs, authentication codes, card-expiry details, and other credentials before restoring the legitimate banking app to limit suspicion.
RemControl abuses Android Accessibility Service permissions to read screens, log input, take screenshots, remotely control infected devices, and hinder removal. Its dropper also misuses VPN permissions to interfere with Google Play Store traffic and Play Protect scanning; newer variants use per-installation signing certificates and custom code packing to evade detection. Group-IB tracks the apparent malware-as-a-service operation as UNKK and found indications that AI assistance was used to build elements of its criminal infrastructure, but said the malware does not use AI on victims’ devices.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
The first known RemControl samples were submitted to VirusTotal, marking the earliest observed samples of the Android banking trojan.
A command-and-control domain used by RemControl was registered.
Investigators found publicly accessible operator documentation that disguised credential theft as quiz-answer handling and remote access as parental monitoring. A complete AI-assistant response left on a live phishing page suggested AI assistance was used for portions of the backend and phishing platform, though not by malware running on victims’ devices.
Group-IB linked RemControl samples to the UNKK affiliate label, which appeared in every sample, and assessed that the operation was offered as malware-as-a-service. The researchers noted possible but unproven connections between UNKK and the Medusa banking-trojan affiliate UNKN.
Researchers found that RemControl uses Android Accessibility permissions and server-hosted banking overlays to capture PINs, banking codes, card-expiry data, screen contents, and typed input, while allowing remote device interaction. Its dropper also used VPN permission to interfere with Play Store traffic and Play Protect scanning, and the malware attempted to block removal through Settings.
Group-IB identified RemControl being distributed through counterfeit Google Play-style TVTap download pages. An observed Italian campaign selectively served malicious installers to Android devices using Italian IP addresses, while the operation targeted customers of more than 30 banks across Europe, the Middle East, and Canada.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.