A new banking trojan for Android, called RemControl, is targeting users in several countries, including Italy.
It is a threat not to be underestimated for those who use their smartphone to manage their account: once installed, the malware can take full control of the device.
Discovered by researchers from Group-IB. RemControl is a malware-as-a-service platform, i.e., malware made available to several criminals as a service, and targets the credentials of bank accounts.
The spread takes place through targeted ads on Meta platforms. Thanks to Tracking Pixel, checks on device type and geolocation, the targeted users are directed to fake Google Play Store pages, which promise to download TVTap for free, a well-known IPTV streaming app. Instead, the dangerous trojan is hidden there.
As soon as the fake app is opened, RemControl starts a local VPN on the device with one purpose: blocking communications with Google Play services. In this way Google Play Protect cannot perform its background scans and does not flag the malicious file.
At that point the malware asks for Android Accessibility permissions. If the user grants them, the phone is effectively compromised: RemControl can record every touch, stream the screen in real time and capture unlock sequences on smartphones Samsung, Xiaomi, Huawei, OPPO, OnePlus and stock Android. And when you try to uninstall it, it automatically closes the Settings menu.
Analyzing the malware infrastructure, which receives commands via encrypted Telegram channels, researchers found documentation for a server exposed online. From there it emerged that RemControl can download over 30 personalized phishing screens, which overlay the banking-app login pages in Spain, Italy, France, Poland, Portugal, Canada and the Middle East.
In one of these phishing pages, still active, there was even the AI model’s response copied and pasted without modifications. The code also contains fragments in Russian and points to a known operator called UNKN, linked to the Medusa Trojan family.
Finally, researchers from Zimperium zLabs identified another Trojan, of Chinese origin and different from RemControl, named RedHat. Traditional banking Trojans stop working when a bank updates the appearance of its app, because they rely on fixed screen coordinates.
RedHat bypasses this issue by sending real-time screenshots to an AI model on the device, which reads the interface and tells the malware where to tap to steal passwords.
For all the latest in the world of security, you can find our most recent articles in GizChina.it’s Security section.
OpenAI has launched a major campaign with social creators, not targeting tech reviewers but those…
Sony has filed a patent that would transform the PlayStation controller into a small payment…
The Xiaomi 18 Pro series becomes compatible with Apple Watch. It's a feature designed for…
Apple and Qualcomm have announced the extension of their global patent licensing agreement, which will…
Google has introduced Live Avatar, a novelty of Gemini 3.8 Live that pairs the assistant's…
For years, users of Apple wearables Apple can capture a screenshot using a simple key…