A new threat in the form of the RemControl banking trojan has been uncovered by cybersecurity experts at Group-IB. This malware abuses the Android Accessibility Service, allowing attackers to seize control of victim devices and steal sensitive banking information, including PIN codes, mobile banking credentials, and card expiry dates. RemControl has been active since July 2026, targeting retail banking customers in Western Europe, the Middle East, and Canada.

The trojan's developer, identified as UNKK, is believed to be a Russian-speaking operator who utilized an AI assistant to develop a significant portion of the trojan's command and control infrastructure and phishing tactics. The AI was reportedly misled into creating API endpoints under the guise of a parental monitoring app. This sophisticated approach has led to a functional fraud platform that disguises credential theft as simple quiz completions.

Victims are tricked into downloading RemControl through fraudulent Google Play Store pages that mimic the TVTap IPTV application. These pages adapt to the user's language and location, increasing the likelihood of successful downloads. Once the app is installed, it requests Accessibility Service permissions, granting the trojan full control of the device. The malware then deploys a series of techniques to evade detection, such as launching a local VPN service and generating a new signing key to bypass hash-based checks.

RemControl's capabilities include overlaying legitimate banking apps with fake interfaces to collect user credentials, capturing screen activities, and logging keystrokes and pattern locks. This allows attackers to map user interactions and extract sensitive information. Additionally, the trojan can prevent removal of the application and block factory reset attempts, ensuring persistent access to the victim's device. Stolen data is sent through a Telegram dead-drop mechanism, further obfuscating the attack's origin.

To combat this threat, Group-IB advises Android users to be cautious about app downloads and to regularly update their security settings to prevent unauthorized access to Accessibility Services.