An emerging threat in mobile cybersecurity has surfaced with the discovery of a new Android banking trojan, RemControl, which utilizes AI to deceive users. This malicious software masquerades as a legitimate streaming app, targeting users’ banking credentials through sophisticated overlays. Researchers have traced its activity back to July 2026 and have identified its widespread impact across numerous banking institutions in Europe, the Middle East, and Canada.
How RemControl Operates
RemControl employs fake download pages resembling Google Play listings to lure victims. These pages, specifically targeting Android devices with Italian IP addresses, deliver the trojan installer concealed within a streaming app. This strategic targeting ensures that only specific users fall prey, while others remain unaffected. Once installed, RemControl can overlay legitimate banking apps with counterfeit interfaces, tricking users into divulging sensitive information such as PINs and passwords.
Beyond merely capturing login credentials, RemControl grants attackers remote access to infected devices. This enables them to monitor screen activity and manipulate controls, posing a significant threat to affected users. The use of AI in creating these deceptive overlays enhances their believability, increasing the risk of successful data theft.
Technical Aspects of the Trojan
The installation process for RemControl involves a series of deceptions, beginning with a fake streaming app update. Users are prompted to grant VPN permissions, which disrupts security checks during installation. Additionally, each installation is accompanied by a new signing certificate, complicating detection efforts based on known files. Post-installation, the trojan requests Android Accessibility access, allowing it to record user interactions and manipulate device settings.
Investigations revealed that RemControl uses Telegram for server communication, allowing operators to dynamically change the server location without modifying the app. This capability, combined with continuously updated overlays, makes it a versatile tool for cybercriminals. The campaign’s infrastructure suggests it may serve as a platform for other malicious actors, providing tools for managing infected devices and harvesting credentials.
Protecting Against RemControl and Similar Threats
To safeguard themselves from threats like RemControl, users should exercise caution when downloading apps from unofficial sources, even if they appear legitimate. It is crucial to scrutinize unexpected requests for VPN or Accessibility permissions and to avoid entering banking information on unprompted screens. If suspicious activity is detected, users are advised to contact their bank immediately through official channels.
This discovery highlights the growing sophistication of mobile threats, with AI playing an increasingly pivotal role in their development. As security measures improve, so do the tactics of attackers, necessitating constant vigilance and updated protection strategies from both users and cybersecurity professionals.
