🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service (MaaS). First observed in July 2026, RemControl abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, capture sensitive credentials, stream the victim’s screen, log interactions, and remotely control the device.
The threat goes beyond credential theft. Its infrastructure includes an exposed operator panel for managing bots, overlay templates, stolen credentials, remote sessions, and affiliate-specific APK builds. The malware also uses a local VPN to interfere with Google Play Protect during installation and retrieves its command-and-control address through an encrypted Telegram dead-drop mechanism.
Researchers also identified evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing page.
Read the full blog.
#CyberSecurity #AndroidMalware #BankingTrojan
Post #995
320

- 🔥 7
- ❤ 4
- ❤🔥 1