Group-IB finds RemControl Android trojan using AI phishing and Play Protect evasion
Group-IB uncovered RemControl, an Android banking trojan spread via fake Google Play pages advertising the TVTap IPTV app through Meta ads. The malware blocks Play Protect with a local VPN, abuses Accessibility permissions for full remote control and uses over 30 AI-assisted phishing overlays targeting banks in Europe, Canada and the Middle East.
- RemControl poses as TVTap and targets banks in Spain, Italy, France, Poland, Portugal, Canada and the Middle East
- A local VPN cuts off Google Play services so Play Protect cannot scan the malicious file
- Accessibility permissions let it record the screen, log taps and block its own uninstall
- Zimperium also found a Chinese trojan RedHat that reads banking UIs in real time via AI
Read next
Security