A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
Although its infrastructure has been active since at least May, researchers first observed samples in July. The samples contained more than 30 phishing overlays designed to steal banking credentials. Group-IB said RemControl targets users in Europe, including Italy, France, Spain, Poland and Portugal, as well as Canada and countries in the Middle East.
One overlay displayed a response from an AI assistant, which Group-IB described as a strong indication that AI models helped build the malware. RemControl is distributed through fake Google Play pages, with at least one Italian campaign using geofencing and mobile User-Agent checks. The sites also contained Meta Pixel tracking IDs, suggesting that the operator abused Meta’s advertising ecosystem to drive users to the download pages.
When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks. The technique was also observed in ToxicPanda, a larger operation using phishing overlays for 349 banking, financial, cryptocurrency and e-wallet applications in 16 countries.
RemControl requests Accessibility Service permissions. It retrieves encrypted command-and-control information from Telegram channels, allowing infrastructure changes during disruptions. Group-IB found exposed FastAPI documentation that revealed endpoints for fetching overlays and submitting stolen credentials. The operator’s origin is unclear. Russian-language HTML suggests that at least some overlays were developed by a Russian speaker. Researchers track the operator as UNKK and suspect a connection to the Medusa banking trojan.
Comments
0No comments yet. Be the first to comment.