RemControl Android banking malware operates as AI‑enhanced Malware‑as‑a‑Service platform targeting banking apps
RemControl is a novel Android banking Trojan that uses AI‑generated overlays and a VPN‑based evasion chain to steal credentials, and it is offered as a Malware‑as‑a‑Service since mid‑2026.

Group‑IB researchers have identified RemControl as a previously unseen Android banking Trojan that functions as a Malware‑as‑a‑Service (MaaS) platform. The first samples date to July 2026 and the command‑and‑control (C2) infrastructure has been active since May 2026. The service includes an affiliate‑tracking API that records the activity of downstream distributors.
The distribution vector relies on counterfeit web pages that mimic the third‑party IPTV application TVTap. These pages were hosted on domains registered on 10 July 2026 and promoted through malvertising campaigns on Facebook and Instagram. The malicious payload is delivered only to Android devices that present a local IP address and a compatible User‑Agent string, limiting exposure to targeted victims.
To bypass Google Play Protect, the dropper first launches a local VPN service that blocks network traffic destined for the package com.android.vending, effectively disabling the Play Store’s real‑time scanning. After the VPN is active, the dropper generates a unique signing certificate and stores it in the Android Keystore, rendering hash‑based and certificate‑based detections ineffective.
RemControl requests the Accessibility Service permission. Once granted, it monitors the foreground application. When a listed banking app is detected, the malware injects a full‑screen WebView overlay that reproduces the legitimate interface. The overlay captures PIN codes, passwords, card expiration dates and even smartphone unlock patterns entered by the user.
Analysis of the code revealed traces of artificial‑intelligence assistance. An AI assistant generated word‑for‑word content for an active phishing page, and comments in Russian along with other artifacts indicate that the overlay HTML and portions of the malicious code were authored with AI support.
Evasion techniques and infrastructure
The VPN‑based bypass and the creation of a per‑installation signing certificate constitute a two‑layer evasion strategy. By preventing Play Store scans and producing a unique certificate for each victim, RemControl avoids detection by traditional mobile security solutions that rely on static signatures.
Command‑and‑control communication is handled through a dead‑drop Telegram channel. This approach allows the operator to rotate C2 endpoints rapidly, complicating attribution and takedown efforts.
Affiliate ecosystem and possible origins
The affiliation metadata includes the pseudonym “UNKK” in campaign tags. Naming conventions and the use of dead‑drop Telegram links resemble the structure of the Medusa botnet, suggesting a potential operational link. Russian‑language comments in the source code point toward a possible Russian origin for the group.
RemControl’s dropper supports more than thirty languages, indicating an intention to expand beyond the currently observed regions. Two variants have been tailored specifically for France, where the malware targets over thirty financial institutions.
- VPN service blocks Play Store traffic to evade Google Play Protect
- Unique signing certificate stored in Android Keystore per victim
- Accessibility Service monitors foreground app and injects full‑screen WebView overlay
- AI‑generated HTML content used for phishing overlay
The AI‑generated overlay is not merely decorative; it reproduces the exact visual elements of targeted banking applications, making manual detection by users difficult. The overlay captures a full set of credential data, including card details and device unlock patterns, which can be exfiltrated to the C2 server.
Because each installation receives a distinct certificate, traditional mobile‑antivirus solutions that rely on hash matching cannot flag the payload consistently. The reliance on dynamic, behavior‑based detection therefore becomes essential for identifying the malicious activity.
Impact measurement challenges
Researchers have not been able to determine the exact number of victims or the financial loss resulting from credential theft. The use of Telegram dead‑drops and per‑victim certificates hampers quantitative analysis, and no public data currently describes the detection rate of existing mobile security products against this campaign.
The lack of concrete impact figures does not diminish the technical sophistication of the operation. The combination of AI‑assisted code generation, multi‑language support, and a robust affiliate infrastructure positions RemControl as a notable threat within the mobile banking malware landscape.
Practical implications for organisations include the need to enforce strict controls over Accessibility Service permissions, to monitor VPN usage on corporate devices, and to adopt behavior‑based mobile threat detection that can spot anomalous overlay injections. Security teams should also scrutinise malvertising channels on social platforms, as the initial infection vector originates from deceptive IPTV‑related pages.
Sources
- RemControl: AI Built the Overlays. Victims Lose their PINs | Group-IB BlogGroup-IB · September 24, 2026
- Cyberattaque IA contre la France et l'Europe : ce virus vise plus de 30 banques01net · September 27, 2026


