Researchers say a new Android banking trojan (“RemControl”) tricks people into installing a fake TVTap app update from spoofed Google Play-style pages. Once installed, it persuades victims to grant Accessibility permissions, giving attackers remote control and enabling theft of banking credentials like PINs and mobile banking codes.
Key findings
- Victims are lured to download the trojan via fake Google Play Store pages impersonating the TVTap IPTV app.
- The app displays a fake “TVTap update” screen and prompts the user to click “install,” leading to malware installation.
- After installation, the trojan asks for Android Accessibility Service permissions; if granted, it enables full device control.
- RemControl uses full-screen overlays to steal banking data (PIN codes, mobile banking codes, card expiry dates) and can keylog and capture screen/UI elements.
- Stolen data is routed via a Telegram “dead-drop” mechanism to obscure the real command-and-control destination.
Who’s being targeted
- Commonly targeted roles: All staff (mobile device users), Finance, Customer support / fraud teams.
- Affected industries: Retail banking, Financial services.
- Attack channels: website.
- Impersonated: Google Play Store / TVTap IPTV application, TVTap app / Android system permission prompt.
Awareness takeaways
- Only install Android apps from the official Google Play Store, not lookalike download pages.
- Treat unexpected Accessibility permission requests as a major warning sign and do not approve them without verification.
- Never enter banking PINs/codes/card details into unexpected pop-up screens or overlays.
Red flags to watch for
- App is downloaded from a “fake Google Play Store page,” not the real Play Store
- Unexpected “update” prompt inside the app via a WebView UI
- Install flow leads to unusual permission prompts shortly after install
- Accessibility permissions requested immediately after installation
- Permissions are excessive/unexpected for an IPTV/streaming app
- Permission enables broad control rather than a specific feature
Read the video transcript
You’re on your Android phone, grab a free TVTap streaming app, and it looks just like Google Play… but it isn’t. You tap install, TVTap opens, and a built‑in update screen pops up: 'New TVTap update – click install.' That click silently drops the RemControl banking trojan on your phone. Next, Android pops an Accessibility permission request. If you allow it, RemControl gets full control, throws full‑screen overlays over your banking app, and records your PINs and mobile banking codes as you type. If any app from outside the real Google Play Store asks for Accessibility, stop and delete it, don’t tap Allow, don’t enter any PINs or codes.