A new threat has emerged for Android users as the RemControl banking trojan uses AI-generated overlays to deceive users into revealing their banking PINs. This malicious software disguises itself as a legitimate app download page for a streaming service that does not actually exist on Google Play. When users attempt to download the app, the trojan waits for a banking app to open, then overlays a fake bank interface to capture sensitive information.

This campaign has been particularly active in Italy, where it targets users by delivering the malicious installer only to those with Italian IP addresses. However, its impact is far-reaching, with over 30 banking institutions across Europe, the Middle East, and Canada identified as having matching phishing screens. Group-IB researchers, who first discovered the trojan’s activity, have traced its origins back to July 2026.

The RemControl trojan is sophisticated, going beyond simple credential theft. It can remotely control an infected device, capturing screen activity and keystrokes. By placing a full-screen overlay over legitimate banking apps, victims are tricked into entering their banking credentials, which are then sent to an attacker-controlled server. This server-based approach allows attackers to change targets dynamically without user intervention.

AI-assisted development is a notable aspect of this attack. Documentation found on the server described stolen banking details as if they were quiz answers, suggesting the use of AI to develop the platform under misleading pretenses. However, AI is not used on the user’s device; the immediate threat remains the convincing fake screens that capture sensitive details.

RemControl further complicates detection by requiring VPN permission to cut off network traffic from the Play Store during installation. It also requests Android Accessibility access, enabling it to read the screen and perform taps or swipes. This misuse of permissions mirrors tactics seen in other banking malware campaigns. Users are advised to scrutinize app permissions, avoid downloading apps from unverified sources, and contact their banks if they suspect any misuse of their accounts.