NewsTradingSentimentEventsCommunityBriefing
Tech

RemControl Malware Steals Banking Data via Fake TV App

By Tech Desk · · 1 min read
A smartphone screen displaying a generic lock icon and a blurred background of a bank building facade

A new Android malware platform uses fake ads to install banking trojans in Europe and Canada, bypassing security checks.

Key points

  • RemControl targets Android users in Europe and Canada using fake TV app ads.
  • The malware steals banking credentials by overlaying fake screens on real apps.
  • It blocks Google security checks and uses Telegram for command updates.

A new Android malware called RemControl is targeting users in Europe and Canada. It spreads through fake advertisements for a TV streaming app. The operation has been active since May.

Researchers at Group-IB identified the threat in July. The software uses over 30 fake screens to steal banking details. It targets countries including Italy, France, and Poland.

Fake ads hide the threat

The malware disguises itself as a popular TV app called TVTap. It appears on fake Google Play pages. Some campaigns use location data to target specific regions.

BleepingComputer reports that the operators used Meta advertising tools. They drove traffic to these malicious download pages. This shows how attackers abuse social media platforms.

How it steals your data

Once installed, the app blocks Google security checks. It asks for special accessibility permissions. If granted, it can control your phone entirely.

It displays fake banking screens on top of real apps. This trick steals passwords and card numbers. It also records your taps and text entries in real time.

The software prevents removal by detecting when you try to uninstall it. It uses encrypted channels on Telegram to receive new commands. This makes it hard to track down.

Developers show AI influence

Some overlays display responses from AI assistants. This suggests AI models helped build the malware. Russian language fragments were found in the code.

Experts link this group to other banking trojans. They advise against downloading apps from outside official stores. Users should deny accessibility requests from unknown apps.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories