Fake TVTap App Used to Steal Banking PINs

Help Net Security · High sophistication
Last updated September 25, 2026

Researchers say the RemControl Android banking trojan tricks people into installing a fake “TVTap” IPTV app from look‑alike Google Play pages promoted via ads. Once installed, it abuses Android permissions to take over the phone, show fake banking login screens, and steal PINs and other banking details while blocking removal attempts.

How the attack worked

The RemControl campaign relies on a fake Google Play Store page impersonating the TVTap IPTV application, a popular third-party app that is not actually available on the official Play Store. Because users are already accustomed to seeking TVTap from unofficial sources, the look-alike page does not raise the same suspicion a fake listing for a mainstream app might. Victims are often driven to these pages through advertising, with researchers finding Meta Pixel tracking codes on the sites suggesting the operator purchased ads on Meta's platform to generate traffic. In at least one campaign targeting Italian bank customers, the malicious app was served only to mobile devices with an Italian IP address, a sign of deliberate geo-targeting.

Once a victim installs the app, a dropper displays a fake TVTap update screen and requests permission to start a VPN service. This VPN blocks network traffic from the Google Play Store app, which prevents Google Play Protect from scanning the installation. The malware then asks for Accessibility Service permission, which gives it control over the device. With that access, RemControl can display fake banking login overlays on top of legitimate banking apps to capture PINs, take screenshots, record clicks and typed text, and remotely control the phone. It can also block attempts to uninstall the app or factory reset the device.

Why it succeeded

The campaign succeeds by exploiting existing user behavior rather than inventing new deception. People already look for TVTap outside official app stores, so a convincing fake listing fits an established habit. Layering in ad-driven distribution and geo-targeted delivery narrows exposure to specific victim populations, which can also help the campaign avoid broader detection. The permission requests, framed as routine steps in an app update flow, allow the attacker to quietly disable built-in protections before the payload is ever exposed to scrutiny.

What to watch for

  • Apps requested from unofficial sources, especially ones not available on the official app store
  • Update prompts that appear immediately after installing a new app
  • Permission requests that do not match the app's stated purpose, such as VPN or Accessibility Service access for a TV or IPTV app
  • Login screens appearing over banking apps unexpectedly

Building resistance

Organizations should reinforce that employees only install apps from official app stores and treat any app sought from unofficial channels as higher risk, particularly for finance teams handling banking credentials. Awareness training should specifically call out that Accessibility Service and VPN permissions are powerful capabilities that legitimate entertainment apps rarely need, and any such request should be treated as a red flag. Encouraging users to question unexpected update prompts, even from apps they intended to install, can help interrupt this attack chain before device takeover occurs. See MITRE ATT&CK technique https://attack.mitre.org/techniques/T1204/002/ for more on user execution via malicious file or app installation.

Key findings

  • RemControl is distributed via fake Google Play Store pages impersonating the TVTap IPTV app, taking advantage of users looking for unofficial downloads.
  • Operators may buy ads on Meta’s platform to drive victims to the malicious download pages (Meta Pixel codes found on the sites).
  • The dropper displays a fake update flow and requests permissions (including a VPN service) to hinder Google Play Protect scanning.
  • After installation, RemControl requests Accessibility Service permission to control the device and overlay fake banking login screens to steal PINs and codes.
  • The malware can capture screenshots, record clicks/typed text, remotely control the device, and block attempts to uninstall or factory reset.
  • C2 server location is retrieved from encrypted text posted in public Telegram channels, enabling fast infrastructure changes.
  • Group-IB tracks the operator as “UNKK” and reports signs of AI-assisted development for the backend and phishing overlays.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile security basics), Finance teams (banking credential hygiene), Executive leadership (risk awareness).
  • Affected industries: Banking, Consumer finance.
  • Attack channels: website.
  • Impersonated: Google Play Store page for “TVTap IPTV application”, TVTap download/Play Store-style page promoted via social media advertising.

Red flags to watch for

  • App is sought from unofficial sources because it “is not available on the Google Play Store”
  • Website only serves the app to specific users (e.g., “mobile devices with an Italian IP address”)
  • Permission requests are unusual for a TV app (VPN service, Accessibility Service)
  • Traffic acquisition via ads to an unofficial app download page
  • Mobile-only / geo-targeted delivery behavior
  • A Play Store “page” that is not actually within the Play Store app
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is RemControl malware?

RemControl is an Android banking trojan distributed through fake Google Play Store pages impersonating the TVTap IPTV app. Once installed, it abuses Accessibility Service permissions to overlay fake banking login screens and steal PINs.

How does the fake TVTap app get installed on phones?

Victims are directed to look-alike Google Play Store pages through ads, since TVTap is a popular app not officially available on the Play Store, making users accustomed to downloading it unofficially. The dropper then shows a fake update screen and requests permissions like VPN and Accessibility Service.

Why does RemControl request VPN permission?

The VPN service blocks network traffic from the Google Play Store app, which stops Google Play Protect from scanning the installation and helps the malware evade detection.

What should users watch for to avoid this type of attack?

Be wary of apps sought from unofficial sources, treat unexpected update prompts as suspicious, and never grant Accessibility Service or VPN permissions to entertainment apps that have no legitimate need for them.

Read the video transcript

You see an ad for “TVTap IPTV” and a Play Store‑looking page pops up on your phone. Looks legit, right? That’s the trap. Researchers found RemControl spreads through fake Google Play Store pages impersonating the TVTap IPTV application, pushed by ads. You tap install, it shows a fake TVTap update, then suddenly asks for VPN and Accessibility Service permissions. That Accessibility permission is the killer: RemControl can take screenshots, record every tap, and pop up fake banking login screens right on top of your real app to steal PINs and codes, while blocking you from uninstalling it. If a TV or entertainment app ever asks for Accessibility Service or VPN, stop. Don’t tap allow, close it, uninstall it, and get your banking app checked by IT.

Similar attacks

EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
RatHat Smishing Lure Pushes Android Sideloading

RatHat Smishing Lure Pushes Android Sideloading

Researchers described an Android Trojan (“RatHat”) that starts with scam texts or malicious ads and tricks people into installing a fake app from a bogus download page. After installation, it pressures victims to grant Accessibility permissions using fake excuses or incentives, then uses those…

September 18, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Gigabud Clones Banking Apps in Hidden Work Profile

Gigabud Clones Banking Apps in Hidden Work Profile

Researchers say the Android banking Trojan “Gigabud” can trick victims into installing a fake app, then create a separate Android work profile and run a cloned banking app inside it. Attackers can perform fraudulent transactions from that cloned app, which may reduce the chance that bank defenses…

September 11, 2026
Gigabud Clones Banking Apps to Dodge Fraud Alerts

Gigabud Clones Banking Apps to Dodge Fraud Alerts

Researchers say the Gigabud Android banking trojan now clones a victim’s real banking app into a hidden Android Work Profile, so fraud can happen in a separate space that may not trigger the same malware and fraud signals. Victims are tricked into installing what looks like legitimate apps…

September 9, 2026
Fake LinkedIn Tests and Job Interviews Push Malware

Fake LinkedIn Tests and Job Interviews Push Malware

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS…

September 7, 2026