
If you use your Android phone for mobile banking, there is a nasty new threat making the rounds. Security researchers at Group-IB recently caught a new malware-as-a-service platform called RemControl in the wild, and it is going after retail banking credentials with a surprisingly clever playbook.
The operators rely on targeted ads across Meta platforms. They use Meta Pixel tracking IDs, mobile User-Agent checks, and geofencing to steer specific victims to fake Google Play Store pages. The trap promises a free download of TVTap, a popular IPTV streaming app, but delivers a full-blown banking trojan instead.
Blinding Play Protect from the moment of install
The moment you open the fake app, RemControl gets right to work. It immediately spins up a local VPN service on the device for one specific reason: to block all network communication with Google Play services. By cutting off that connection, Google Play Protect cannot run its background scans to flag the malicious file.
This exact evasion tactic was also recently spotted in new variants of ToxicPanda, a massive malware operation targeting 349 financial and crypto apps across 16 countries. Once the built-in antivirus is effectively blinded, RemControl asks for Android Accessibility permissions.
If a user grants those rights, the phone is essentially compromised. The malware can log every single tap, stream screen recordings in real time, and capture unlock patterns on phones from Samsung, Xiaomi, Huawei, OPPO, OnePlus, and stock Android. It even blocks any attempt to uninstall it by auto-closing the settings menu as soon as you try to tap it open (via Bleepingcomputer).
AI lazy slips, Telegram channels, and the RedHat threat
What makes RemControl stand out is how it was built. While digging through the malware’s backend infrastructure—which uses encrypted Telegram channels to fetch new commands—researchers found exposed FastAPI documentation on the initial proxy server. This revealed endpoints used to pull down over 30 custom phishing overlays targeting bank accounts in Spain, Italy, France, Poland, Portugal, Canada, and the Middle East.
They also found a funny, yet alarming mistake. More specifically, there’s an unedited response from an AI model left copy-pasted verbatim right inside a live phishing page. The campaign carries Russian language snippets in its HTML code and tracks back to an operator known as UNKN, linked to the Medusa trojan family.
To make matters worse, researchers at Zimperium zLabs spotted another new Chinese trojan named RedHat that takes AI integration even further. Traditional banking trojans break if a bank updates its app layout because the malware relies on hardcoded screen coordinates. RedHat solves this by feeding live screenshots to an onboard AI model, which reads the UI in real time and tells the malware exactly where to click to steal passwords.
The post A New Android Banking Trojan Is Using AI and Fake Play Store Pages to Rob Users appeared first on Android Headlines.
​Â