Back to Newsroom
Threat Intel

New RemControl Android Trojan Hides Inside a Fake Streaming App to Steal Banking PINs

A trojanized clone of the TVTap streaming app is installing RemControl, an Android banking trojan that throws fake bank login screens over real apps to steal PINs, codes, and card details.

New RemControl Android Trojan Hides Inside a Fake Streaming App to Steal Banking PINs

A newly documented Android banking trojan, tracked as RemControl, is spreading disguised as a free IPTV/streaming app called TVTap, using convincing fake Google Play pages to trick users — mainly in Italy and France so far — into installing malware that hijacks their banking sessions.

What happened

Attackers built lookalike Google Play listings advertising "TVTap: Film, TV e Calcio," complete with fake ratings, screenshots, and inflated download counts. Instead of routing through the real Play Store, the page pushes a direct APK download. On first launch, the app shows a fake "update required" screen, requests VPN permission to interfere with real-time Play Protect scanning, and each build ships with a freshly generated signing certificate to dodge hash-based detection. It then asks for Android Accessibility access — the single most abused capability among modern banking trojans — which lets it read the screen, log keystrokes, capture screenshots, and simulate taps on the operator's behalf.

Once installed, RemControl checks in with an attacker-controlled server that pushes full-screen overlays mimicking real banking apps. When a victim opens their genuine bank app, RemControl throws a convincing fake login or PIN screen on top of it. The victim enters their PIN, mobile banking code, or card details into the fake screen, which then closes to reveal the real — now compromised — app underneath. Because the overlays are fetched live from the server rather than bundled into the app, operators can swap in new banks or new targets at any time without shipping a new build.

Investigators also found signs the group used an AI assistant to help build backend tooling for the operation: internal documentation referred to stolen banking data as "quiz answers" and the remote-control features as "parental monitoring," and a live phishing page was found with a complete AI assistant reply — notes and an offer to build more — left embedded inside it. The malware itself doesn't use AI on the infected phone; the operators appear to have used AI coding assistance to build and disguise the platform.

The operation runs like a for-hire service: an exposed control panel let affiliates generate new malicious builds, manage infected devices, and view captured credentials, with one affiliate tracked under the label "UNKK." Rather than hardcoding its command server, the malware pulls the current address from a Telegram dead-drop, letting operators rotate infrastructure at will without touching the app itself.

Why it matters

This isn't a simple credential grab. Accessibility abuse combined with live screen capture and remote tap injection means an infected device becomes a fully remote-controllable fraud tool — capable of authenticating transactions, reading one-time codes, and hiding fraudulent activity behind fake screens, well beyond a single stolen PIN. Distribution through convincing fake app-store pages, rather than sideloading forums, also shows the attackers investing as much in the social-engineering layer as in the payload itself.

What to do

  • Only install apps from the official Google Play Store on the device itself — never from a link, ad, or lookalike download page, even one that looks pixel-perfect.
  • Treat unexpected VPN or Accessibility permission requests from streaming/media apps as a red flag; legitimate apps in that category don't need them.
  • Never enter a banking PIN, mobile code, or card detail into a screen that appears unprompted, even if it looks identical to your bank's real app.
  • If you suspect a device is compromised, uninstall the suspicious app, run a mobile security scan, and contact your bank through its official app or phone number to review recent activity and revoke active sessions.
  • Security teams should treat per-install signing certificates and messaging-platform-based C2 resolution as evasion patterns worth hunting for across managed mobile fleets.
SHARE