Skip to main content

New RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing Overlays

0
Medium
Published: 09/24/2026 (09/24/2026, 12:41:17 UTC)
Source: AlienVault OTX General

Description

RemControl is an Android banking trojan first observed in July 2026 that targets financial institutions across Western Europe, the Middle East, and Canada. The malware is distributed through fake Google Play Store pages advertising TVTap, an IPTV application, using malvertising campaigns with geo-targeted delivery. Once installed, the dropper creates a local VPN to block Play Protect checks and generates unique signing certificates per installation. RemControl exploits Android Accessibility Service permissions to display phishing overlays for over 30 banking applications, capturing PINs, mobile banking codes, and card details. The malware includes remote control capabilities, screen streaming, keylogging, and lock-screen pattern capture. It operates as Malware-as-a-Service with infrastructure showing evidence of AI-assisted development in phishing page creation and documentation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 19:48:32 UTC

Technical Analysis

RemControl is a sophisticated Android banking trojan that emerged in mid-2026, targeting users primarily in Western Europe, the Middle East, and Canada. It is distributed through deceptive fake Google Play Store pages promoting the TVTap IPTV application, leveraging geo-targeted malvertising campaigns. Upon installation, the malware deploys a local VPN to circumvent Google Play Protect security checks and generates unique signing certificates for each infection instance. It exploits Android Accessibility Service permissions to overlay phishing screens on more than 30 banking applications, enabling the theft of sensitive information such as PINs, mobile banking codes, and card details. The trojan also includes advanced features like remote control of the device, screen streaming, keylogging, and capturing lock-screen patterns. The infrastructure behind RemControl indicates it is offered as Malware-as-a-Service with evidence of AI-assisted development to enhance phishing overlay creation and documentation.

Potential Impact

The trojan can steal sensitive banking credentials including PINs, mobile banking codes, and card details by displaying phishing overlays on legitimate banking apps. It can also monitor user activity through keylogging, screen streaming, and lock-screen pattern capture, potentially leading to unauthorized access to financial accounts and identity theft. The use of local VPN to block security checks increases persistence and evasion capabilities.

Defensive Guidance

No official patch or remediation guidance is provided. Users should avoid installing applications from unofficial or suspicious sources such as fake Google Play Store pages. Monitoring for unusual VPN usage and restricting Accessibility Service permissions to trusted applications can help reduce risk. Since this is malware, standard mobile security best practices and endpoint protection solutions may help detect and remove infections.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberpress.org/remcontrol-trojan-steals-banking-pins/?amp=1"]
Pulse Id
6ab51a6d40cabb350f8e954b

Indicators of Compromise

Domain

ValueDescriptionCopy
domainvpn.doneplay.site
—

Threat ID: 6ab57aedf7a7c54106bff427

Added to database: 09/24/2026, 19:33:01 UTC

Last enriched: 09/24/2026, 19:48:32 UTC

Last updated: 09/25/2026, 01:47:53 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses