TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #995 320
🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service (MaaS). First observed in July 2026, RemControl abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, capture sensitive credentials, stream the victim’s screen, log interactions, and remotely control the device.

The threat goes beyond credential theft. Its infrastructure includes an exposed operator panel for managing bots, overlay templates, stolen credentials, remote sessions, and affiliate-specific APK builds. The malware also uses a local VPN to interfere with Google Play Protect during installation and retrieves its command-and-control address through an encrypted Telegram dead-drop mechanism.

Researchers also identified evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing page.

Read the full blog.

#CyberSecurity #AndroidMalware #BankingTrojan
  • 🔥 7
  • ❤ 4
  • ❤‍🔥 1
More from @group_ib
  1. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  2. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  3. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  4. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  5. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
  6. Aug 27, 2026🚨 By the time a bank detects fraud, legacy systems are simply watching the end of a story…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →