A new Android banking trojan called RemControl is being distributed through fake Google Play pages pretending to offer the TVTap IPTV app. After victims install it and grant powerful Accessibility permissions, it can place fake login screens over real banking apps and give attackers remote control of the device. This provides a realistic, repeatable social-engineering workflow that can be used for awareness simulations (malicious app install + permission prompts + banking credential capture).
How the attack worked
The RemControl campaign begins with a lookalike download page designed to look like Google Play, offering the TVTap IPTV app. Victims who download and install the app are then prompted to grant Accessibility permissions, a step that seems routine but hands the malware deep control over the device. Once granted, RemControl can display phishing overlays on top of legitimate banking apps, log keystrokes, stream the screen to attackers, and enable full remote control of the phone. This turns a simple app install into a complete credential theft and device takeover pipeline, targeting customers of more than 30 banks across Western Europe, the Middle East, and Canada.
Why it succeeded
The attack works because each step looks plausible in isolation. A fake Play Store page for a popular streaming app doesn't look inherently dangerous, and permission prompts are something Android users are used to clicking through quickly. By the time a fake banking login overlay appears asking the user to "sign in again," the malware is already positioned to capture whatever is typed. RemControl is offered as malware-as-a-service, which suggests the workflow is being packaged and reused rather than built for a single one-off campaign.
What to watch for
- Apps offered through a lookalike or third-party "Google Play" page rather than the official store
- A streaming or IPTV app asking for Accessibility permissions, which it has no legitimate need for
- Sudden "please sign in again" prompts appearing while using a banking app, especially after installing a new app
- Overlay screens that behave oddly, such as unusual layouts or an inability to navigate back normally
Building resistance
The most effective defense is treating app installs and permission prompts as security decisions, not routine taps. Employees and consumers alike should only install apps from official stores and be skeptical of download pages that route around them. Accessibility permission requests deserve particular scrutiny: if an app's stated purpose doesn't require that level of access, denying the request and uninstalling the app is the safer choice. Finally, anyone who sees an unexpected banking login prompt should stop, close the app, and re-open their banking app through its normal, trusted path rather than typing credentials into whatever screen appeared. Techniques like this map to MITRE ATT&CK T1204.002 (user execution of a malicious file) and T1656 (impersonation), both of which rely on the user completing the final step themselves.
Key findings
- RemControl is an Android banking trojan offered as malware-as-a-service.
- It spreads via fake Google Play pages for the TVTap IPTV app.
- After Accessibility permissions are granted, it can display phishing overlays on banking apps, log keystrokes, stream the screen, and enable full remote control.
- The campaign targets customers of more than 30 banks across multiple regions (Western Europe, Middle East, Canada).
Who’s being targeted
- Commonly targeted roles: All Employees, Finance teams, Anyone using Android devices for personal or work banking.
- Affected industries: Banking/Financial Services, Consumers/Mobile Users.
- Attack channels: website.
- Impersonated: Google Play / TVTap app listing, Victim’s mobile banking app (overlay impersonation).
Red flags to watch for
- App is offered via a lookalike/third-party ‘Google Play’ page rather than the official store
- Unexpected request for Accessibility permissions for a TV/streaming app
- App behavior includes screen capture/remote control prompts that don’t match the app’s purpose
- A sudden ‘re-login’ prompt appears unexpectedly while using the banking app
- Overlay screens don’t behave like normal app pages (e.g., odd layout, can’t navigate back normally)
- Request occurs after the user recently granted powerful permissions to a non-banking app
Frequently asked questions
How does the RemControl trojan infect Android devices?
It spreads through fake Google Play pages offering the TVTap IPTV app. Once installed, victims are prompted to grant Accessibility permissions, which the malware then abuses.
What can RemControl do once installed?
After Accessibility permissions are granted, it can display phishing overlays on top of banking apps, log keystrokes, stream the screen, and give the operator full remote control of the device.
Who is being targeted by this campaign?
The campaign targets customers of more than 30 banks across Western Europe, the Middle East, and Canada, meaning any Android user doing personal or work banking on their phone could be affected.
What is the biggest red flag to watch for?
An unexpected request for Accessibility permissions from an app that has no real reason to need them, such as a streaming or IPTV app, is a major warning sign.
Read the video transcript
You tap a Google Play page for “TVTap IPTV, fast, free streaming”… and that tap just handed over your bank. Behind that fake page is RemControl, an Android banking trojan. You install “TVTap”, and it instantly begs for Accessibility permissions it should never need, then it can watch your screen, log keystrokes, and let someone drive your phone remotely. Later, you open your banking app and a full-screen message pops up: “For your security, please sign in again to continue.” That’s RemControl placing a fake login overlay on top of your real app to grab your credentials while it streams your screen. Here’s the move: if any non-banking app, like a TV or streaming app, asks for Accessibility permissions, stop, deny it, and uninstall the app immediately.