Post

New RemControl Android Banking Malware Targets Users in Europe and Canada

New RemControl Android Banking Malware Targets Users in Europe and Canada

New RemControl Android Banking Malware Targets Users in Europe and Canada

A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials. Researchers at cybersecurity company Group-IB say that the malware targets users in Europe (Italy, France, Spain, Poland, Portugal), Canada, and countries in the Middle East. RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.

When launched, the dropper starts a VPN service that blocks traffic from Google Play services, preventing Play Protect from performing real-time checks against known malware. During installation, the malware requests approval for Accessibility Service permissions. If the requested permissions are granted, RemControl can perform the following actions:

  • Display full-screen phishing overlays on top of legitimate banking apps and steal PINs, banking codes, card expiry dates, and credentials.
  • Dynamically receive new banking targets from the command-and-control (C2) infrastructure.
  • Stream screenshots and the full Android accessibility/UI tree to the operator in real time.
  • Remotely perform taps, swipes, scrolling, gestures, long presses, and text injection.
  • Prevent removal by detecting when victims enter application-management, accessibility, or factory-reset settings and automatically exiting.

RemControl retrieves encrypted C2 information from Telegram channels, allowing it to rotate infrastructure dynamically in case of disruptions. Group-IB found FastAPI documentation exposed in the initial C2 proxy that revealed the endpoints the malware used to fetch banking overlays and to submit stolen credentials.

The origin of the threat actor behind RemControl is unclear, but researchers found Russian language in the HTML files of some overlays, indicating a Russian speaker as the developer of at least some of them. Based on a common identifier in the analyzed samples, the researchers track the RemControl operator as UNKK and suspect a connection to the Medusa banking trojan.

Android users are advised to avoid downloading APK files from outside Google Play unless they explicitly trust the publisher. Regular Play Protect scans and declining Accessibility Service permission requests from apps that do not require them for accessibility purposes are also recommended security practices.

Read full article

This post is licensed under CC BY 4.0 by the author.