RemControl: AI Built the Overlays. Victims Lose their PINs
RemControl is an Android banking trojan operating as Malware-as-a-Service since May 2026. It targets over 30 financial institutions in Western Europe, the Middle East, and Canada via fake IPTV download pages distributed through malvertising. The malware abuses Android Accessibility Service to inject phishing overlays, stream device screens, log keystrokes, and enable full remote control. The criminal infrastructure was partially built using AI assistance, with AI-generated content found in phishing pages. The threat actor UNKK operates the campaigns, with possible links to the Medusa UNKN affiliate botnet.
AI Analysis
Technical Summary
RemControl is a previously undocumented Android banking trojan discovered by Group-IB researchers. It has been active since May 2026 and targets more than 30 financial institutions across Western Europe, the Middle East, and Canada. Infection vectors include fake TVTap IPTV download pages distributed via malvertising. The trojan abuses Android Accessibility Service to perform overlay injection for phishing, real-time screen streaming, keystroke logging, and full remote control of infected devices. The malware's criminal infrastructure was built with AI assistance, including verbatim AI-generated phishing page content. The C2 panel documentation misleadingly refers to credential theft as quiz completion, indicating deception of AI tools during development. The threat actor UNKK is responsible for the campaigns, with potential ties to the Medusa UNKN affiliate botnet based on infrastructure similarities.
Potential Impact
The trojan enables attackers to steal banking credentials by overlaying phishing interfaces on legitimate apps, capture keystrokes, and remotely control infected devices. This can lead to unauthorized access to victims' bank accounts and financial loss. The use of Accessibility Service abuse and screen streaming increases the stealth and effectiveness of the malware. The targeting of multiple financial institutions across several regions broadens the potential victim base.
Mitigation Recommendations
No official patch or remediation is available as this is malware targeting Android devices. Mitigation involves user awareness to avoid downloading apps from untrusted sources, especially fake IPTV download pages promoted via malvertising. Security solutions should monitor for Accessibility Service abuse and suspicious overlay behavior. Users should verify app legitimacy before installation and avoid clicking on suspicious ads or links.
Affected Countries
Canada
Indicators of Compromise
- hash: f9e6ea83e50b72a081aef44d22f19bcf
- hash: b60cee64202c6ad48808c10226093540292ae4b8
- hash: 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1
- hash: 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7
- hash: 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c
- hash: 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb
- hash: 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1
- hash: 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d
- hash: 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4
- hash: 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1
- hash: 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b
- hash: 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a
- hash: 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f
- hash: ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f
- hash: af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c
- hash: b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3
- hash: c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0
- hash: cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889
- hash: dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730
- hash: fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e
- ip: 216.126.229.216
- domain: bnbnhura.top
- domain: definatelynoone.com
- domain: tvtap-liveapp.com
- domain: cdn.dlmafi.top
- domain: ff-de.shutgpt.ir
- domain: vpn.askarzadeh.com
- domain: vpn.doneplay.site
RemControl: AI Built the Overlays. Victims Lose their PINs
Description
RemControl is an Android banking trojan operating as Malware-as-a-Service since May 2026. It targets over 30 financial institutions in Western Europe, the Middle East, and Canada via fake IPTV download pages distributed through malvertising. The malware abuses Android Accessibility Service to inject phishing overlays, stream device screens, log keystrokes, and enable full remote control. The criminal infrastructure was partially built using AI assistance, with AI-generated content found in phishing pages. The threat actor UNKK operates the campaigns, with possible links to the Medusa UNKN affiliate botnet.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RemControl is a previously undocumented Android banking trojan discovered by Group-IB researchers. It has been active since May 2026 and targets more than 30 financial institutions across Western Europe, the Middle East, and Canada. Infection vectors include fake TVTap IPTV download pages distributed via malvertising. The trojan abuses Android Accessibility Service to perform overlay injection for phishing, real-time screen streaming, keystroke logging, and full remote control of infected devices. The malware's criminal infrastructure was built with AI assistance, including verbatim AI-generated phishing page content. The C2 panel documentation misleadingly refers to credential theft as quiz completion, indicating deception of AI tools during development. The threat actor UNKK is responsible for the campaigns, with potential ties to the Medusa UNKN affiliate botnet based on infrastructure similarities.
Potential Impact
The trojan enables attackers to steal banking credentials by overlaying phishing interfaces on legitimate apps, capture keystrokes, and remotely control infected devices. This can lead to unauthorized access to victims' bank accounts and financial loss. The use of Accessibility Service abuse and screen streaming increases the stealth and effectiveness of the malware. The targeting of multiple financial institutions across several regions broadens the potential victim base.
Defensive Guidance
No official patch or remediation is available as this is malware targeting Android devices. Mitigation involves user awareness to avoid downloading apps from untrusted sources, especially fake IPTV download pages promoted via malvertising. Security solutions should monitor for Accessibility Service abuse and suspicious overlay behavior. Users should verify app legitimacy before installation and avoid clicking on suspicious ads or links.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/remcontrol-android-banking-trojan/"]
- Adversary
- UNKK
- Pulse Id
- 6ab3c7511ba65533d7e207ce
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashf9e6ea83e50b72a081aef44d22f19bcf | — | |
hashb60cee64202c6ad48808c10226093540292ae4b8 | — | |
hash19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 | — | |
hash1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 | — | |
hash28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c | — | |
hash3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb | — | |
hash45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 | — | |
hash54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d | — | |
hash5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 | — | |
hash648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 | — | |
hash76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b | — | |
hash77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a | — | |
hash95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f | — | |
hashad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f | — | |
hashaf2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c | — | |
hashb714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 | — | |
hashc6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 | — | |
hashcb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 | — | |
hashdd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 | — | |
hashfa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip216.126.229.216 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainbnbnhura.top | — | |
domaindefinatelynoone.com | — | |
domaintvtap-liveapp.com | — | |
domaincdn.dlmafi.top | — | |
domainff-de.shutgpt.ir | — | |
domainvpn.askarzadeh.com | — | |
domainvpn.doneplay.site | — |
Threat ID: 6ab3d50cf7a7c54106d5e5cd
Added to database: 09/23/2026, 13:33:00 UTC
Last enriched: 09/23/2026, 13:51:31 UTC
Last updated: 09/23/2026, 13:54:18 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.