Skip to main content

RemControl: AI Built the Overlays. Victims Lose their PINs

0
Medium
Published: 09/23/2026 (09/23/2026, 12:34:25 UTC)
Source: AlienVault OTX General

Description

RemControl is an Android banking trojan operating as Malware-as-a-Service since May 2026. It targets over 30 financial institutions in Western Europe, the Middle East, and Canada via fake IPTV download pages distributed through malvertising. The malware abuses Android Accessibility Service to inject phishing overlays, stream device screens, log keystrokes, and enable full remote control. The criminal infrastructure was partially built using AI assistance, with AI-generated content found in phishing pages. The threat actor UNKK operates the campaigns, with possible links to the Medusa UNKN affiliate botnet.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 13:51:31 UTC

Technical Analysis

RemControl is a previously undocumented Android banking trojan discovered by Group-IB researchers. It has been active since May 2026 and targets more than 30 financial institutions across Western Europe, the Middle East, and Canada. Infection vectors include fake TVTap IPTV download pages distributed via malvertising. The trojan abuses Android Accessibility Service to perform overlay injection for phishing, real-time screen streaming, keystroke logging, and full remote control of infected devices. The malware's criminal infrastructure was built with AI assistance, including verbatim AI-generated phishing page content. The C2 panel documentation misleadingly refers to credential theft as quiz completion, indicating deception of AI tools during development. The threat actor UNKK is responsible for the campaigns, with potential ties to the Medusa UNKN affiliate botnet based on infrastructure similarities.

Potential Impact

The trojan enables attackers to steal banking credentials by overlaying phishing interfaces on legitimate apps, capture keystrokes, and remotely control infected devices. This can lead to unauthorized access to victims' bank accounts and financial loss. The use of Accessibility Service abuse and screen streaming increases the stealth and effectiveness of the malware. The targeting of multiple financial institutions across several regions broadens the potential victim base.

Defensive Guidance

No official patch or remediation is available as this is malware targeting Android devices. Mitigation involves user awareness to avoid downloading apps from untrusted sources, especially fake IPTV download pages promoted via malvertising. Security solutions should monitor for Accessibility Service abuse and suspicious overlay behavior. Users should verify app legitimacy before installation and avoid clicking on suspicious ads or links.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/remcontrol-android-banking-trojan/"]
Adversary
UNKK
Pulse Id
6ab3c7511ba65533d7e207ce

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf9e6ea83e50b72a081aef44d22f19bcf
hashb60cee64202c6ad48808c10226093540292ae4b8
hash19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1
hash1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7
hash28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c
hash3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb
hash45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1
hash54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d
hash5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4
hash648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1
hash76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b
hash77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a
hash95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f
hashad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f
hashaf2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c
hashb714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3
hashc6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0
hashcb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889
hashdd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730
hashfa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e

Ip

ValueDescriptionCopy
ip216.126.229.216

Domain

ValueDescriptionCopy
domainbnbnhura.top
domaindefinatelynoone.com
domaintvtap-liveapp.com
domaincdn.dlmafi.top
domainff-de.shutgpt.ir
domainvpn.askarzadeh.com
domainvpn.doneplay.site

Threat ID: 6ab3d50cf7a7c54106d5e5cd

Added to database: 09/23/2026, 13:33:00 UTC

Last enriched: 09/23/2026, 13:51:31 UTC

Last updated: 09/23/2026, 13:54:18 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses