Researchers say the RemControl Android banking trojan tricks people into installing a fake “TVTap” IPTV app from look‑alike Google Play pages promoted via ads. Once installed, it abuses Android permissions to take over the phone, show fake banking login screens, and steal PINs and other banking details while blocking removal attempts.
How the attack worked
The RemControl campaign relies on a fake Google Play Store page impersonating the TVTap IPTV application, a popular third-party app that is not actually available on the official Play Store. Because users are already accustomed to seeking TVTap from unofficial sources, the look-alike page does not raise the same suspicion a fake listing for a mainstream app might. Victims are often driven to these pages through advertising, with researchers finding Meta Pixel tracking codes on the sites suggesting the operator purchased ads on Meta's platform to generate traffic. In at least one campaign targeting Italian bank customers, the malicious app was served only to mobile devices with an Italian IP address, a sign of deliberate geo-targeting.
Once a victim installs the app, a dropper displays a fake TVTap update screen and requests permission to start a VPN service. This VPN blocks network traffic from the Google Play Store app, which prevents Google Play Protect from scanning the installation. The malware then asks for Accessibility Service permission, which gives it control over the device. With that access, RemControl can display fake banking login overlays on top of legitimate banking apps to capture PINs, take screenshots, record clicks and typed text, and remotely control the phone. It can also block attempts to uninstall the app or factory reset the device.
Why it succeeded
The campaign succeeds by exploiting existing user behavior rather than inventing new deception. People already look for TVTap outside official app stores, so a convincing fake listing fits an established habit. Layering in ad-driven distribution and geo-targeted delivery narrows exposure to specific victim populations, which can also help the campaign avoid broader detection. The permission requests, framed as routine steps in an app update flow, allow the attacker to quietly disable built-in protections before the payload is ever exposed to scrutiny.
What to watch for
- Apps requested from unofficial sources, especially ones not available on the official app store
- Update prompts that appear immediately after installing a new app
- Permission requests that do not match the app's stated purpose, such as VPN or Accessibility Service access for a TV or IPTV app
- Login screens appearing over banking apps unexpectedly
Building resistance
Organizations should reinforce that employees only install apps from official app stores and treat any app sought from unofficial channels as higher risk, particularly for finance teams handling banking credentials. Awareness training should specifically call out that Accessibility Service and VPN permissions are powerful capabilities that legitimate entertainment apps rarely need, and any such request should be treated as a red flag. Encouraging users to question unexpected update prompts, even from apps they intended to install, can help interrupt this attack chain before device takeover occurs. See MITRE ATT&CK technique https://attack.mitre.org/techniques/T1204/002/ for more on user execution via malicious file or app installation.
Key findings
- RemControl is distributed via fake Google Play Store pages impersonating the TVTap IPTV app, taking advantage of users looking for unofficial downloads.
- Operators may buy ads on Meta’s platform to drive victims to the malicious download pages (Meta Pixel codes found on the sites).
- The dropper displays a fake update flow and requests permissions (including a VPN service) to hinder Google Play Protect scanning.
- After installation, RemControl requests Accessibility Service permission to control the device and overlay fake banking login screens to steal PINs and codes.
- The malware can capture screenshots, record clicks/typed text, remotely control the device, and block attempts to uninstall or factory reset.
- C2 server location is retrieved from encrypted text posted in public Telegram channels, enabling fast infrastructure changes.
- Group-IB tracks the operator as “UNKK” and reports signs of AI-assisted development for the backend and phishing overlays.
Who’s being targeted
- Commonly targeted roles: All employees (mobile security basics), Finance teams (banking credential hygiene), Executive leadership (risk awareness).
- Affected industries: Banking, Consumer finance.
- Attack channels: website.
- Impersonated: Google Play Store page for “TVTap IPTV application”, TVTap download/Play Store-style page promoted via social media advertising.
Red flags to watch for
- App is sought from unofficial sources because it “is not available on the Google Play Store”
- Website only serves the app to specific users (e.g., “mobile devices with an Italian IP address”)
- Permission requests are unusual for a TV app (VPN service, Accessibility Service)
- Traffic acquisition via ads to an unofficial app download page
- Mobile-only / geo-targeted delivery behavior
- A Play Store “page” that is not actually within the Play Store app
Frequently asked questions
What is RemControl malware?
RemControl is an Android banking trojan distributed through fake Google Play Store pages impersonating the TVTap IPTV app. Once installed, it abuses Accessibility Service permissions to overlay fake banking login screens and steal PINs.
How does the fake TVTap app get installed on phones?
Victims are directed to look-alike Google Play Store pages through ads, since TVTap is a popular app not officially available on the Play Store, making users accustomed to downloading it unofficially. The dropper then shows a fake update screen and requests permissions like VPN and Accessibility Service.
Why does RemControl request VPN permission?
The VPN service blocks network traffic from the Google Play Store app, which stops Google Play Protect from scanning the installation and helps the malware evade detection.
What should users watch for to avoid this type of attack?
Be wary of apps sought from unofficial sources, treat unexpected update prompts as suspicious, and never grant Accessibility Service or VPN permissions to entertainment apps that have no legitimate need for them.
Read the video transcript
You see an ad for “TVTap IPTV” and a Play Store‑looking page pops up on your phone. Looks legit, right? That’s the trap. Researchers found RemControl spreads through fake Google Play Store pages impersonating the TVTap IPTV application, pushed by ads. You tap install, it shows a fake TVTap update, then suddenly asks for VPN and Accessibility Service permissions. That Accessibility permission is the killer: RemControl can take screenshots, record every tap, and pop up fake banking login screens right on top of your real app to steal PINs and codes, while blocking you from uninstalling it. If a TV or entertainment app ever asks for Accessibility Service or VPN, stop. Don’t tap allow, close it, uninstall it, and get your banking app checked by IT.