VYPR
researchPublished Sep 24, 2026· 2 sources

RemControl Android Trojan Leverages AI-Assisted Development for Sophisticated Banking PIN Theft

A new Android banking trojan named RemControl uses AI-assisted development to create convincing fake login screens for over 30 financial institutions, tricking users into revealing sensitive banking PINs and credentials.

A novel Android banking trojan, dubbed RemControl, has emerged, employing sophisticated techniques to pilfer users' banking credentials. Researchers at Group-IB have identified this malware, which was first observed in July 2026. RemControl operates by masquerading as a legitimate streaming application, luring unsuspecting users into downloading a malicious installer from fake Google Play-like pages. These pages are often geo-targeted, as seen in an Italian campaign where only users with Italian IP addresses were presented with the malicious download, effectively hiding the threat from broader observation.

The primary objective of RemControl is to steal banking PINs and other sensitive login information. Once installed, it waits for targeted banking applications to be launched. Upon detection, the trojan overlays a convincing, full-screen replica of the bank's login interface, prompting the user to enter their PIN, mobile banking code, or card expiry date. After the victim submits their details, the fake screen disappears, and the legitimate banking app reappears, leaving the user unaware that their credentials have been compromised. The fake interfaces are dynamically loaded from an attacker-controlled server, allowing for easy updates and target switching without requiring users to download new malicious files.

What sets RemControl apart is the evidence suggesting the use of AI-assisted development in its creation. Server documentation discovered by investigators referred to stolen banking details as "quiz answers" and remote access capabilities as "parental monitoring." A complete AI assistant response, offering further assistance, was found within a live phishing page. While the malware itself does not appear to utilize AI on the infected device, these findings strongly indicate that an AI assistant was used to build parts of the criminal platform under deceptive pretenses, highlighting a growing trend of AI being weaponized for malicious purposes.

The installation process is designed to evade detection. The initial dropper presents itself as a fake streaming app update. It then requests VPN permissions and manipulates network traffic during installation to interfere with real-time security checks from the Google Play Store. Each installation is equipped with a newly generated signing certificate, making file-based detection more challenging. Following installation, the trojan seeks Android Accessibility access, a powerful permission that allows it to read screen content, capture screenshots, and simulate user input, effectively granting operators remote control over the device.

Beyond credential theft, RemControl possesses extensive remote control and surveillance capabilities. It can log keystrokes, inspect on-screen controls, and capture screenshots. The malware is also capable of gathering information to reconstruct device unlock patterns and can prevent users from removing its permissions by pushing them out of settings screens. This broad range of functionalities extends the threat beyond simple PIN theft, enabling comprehensive device compromise.

RemControl appears to be offered as a service to other cybercriminals. An exposed control panel provided tools for building malicious applications, managing infected devices, and viewing captured credentials. While the observed samples were linked to an affiliate known as UNKK, a potential connection to another banking malware network remains unconfirmed. The malware dynamically fetches its command-and-control server location via Telegram, allowing operators to quickly change communication endpoints without needing to recompile the application, further enhancing its evasiveness.

This operation aligns with a broader trend of banking PIN theft that combines deceptive interfaces with advanced device control. Users are strongly advised to exercise extreme caution when downloading apps from sources other than official app stores and to be wary of unexpected permission requests, particularly for VPN and Accessibility services. Entering banking details should only be done within known, legitimate applications and never on screens that appear unexpectedly. Promptly contacting banks through official channels is crucial if any account misuse is suspected.

This new report from Help Net Security details how RemControl distributes itself via fake Google Play Store pages impersonating the TVTap IPTV application, a tactic designed to lure users accustomed to obtaining such apps from unofficial sources. The malware employs a sophisticated method of circumventing Google Play Protect by requesting VPN permissions that block Play Store traffic, allowing it to install itself with a custom certificate and bypass hash-based detection.

Synthesized by Vypr AI