RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App

RemControl Android Banking Trojan Targets Italy and France (TL-2026-2625), also tracked as RemControlApp, is a high-severity malware campaign, first published 2026-09-23. It is attributed to UNKK with low confidence, affects Google Android OS (devices permitting sideloaded/unofficial APK, maps to 18 MITRE ATT&CK techniques (T1406, T1417.001, T1417.002), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-2625

Threat ID
TL-2026-2625
Also known as
RemControlApp
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-23
Last reviewed
2026-09-23
Attribution
UNKK
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial-services, banking
Target regions
italy, france, spain, poland, portugal, canada, GCC states
Detection rules
9
Indicators of compromise
25

Malware and tooling in RemControl Android Banking Trojan Targets Italy and France

Malware and tooling: MEDUSA - S1220, RemControl, FastAPI (Cloudflare-fronted)

Group-IB identified RemControl, an Android banking trojan with full remote-access capabilities distributed through fake Google Play Store pages and malvertising impersonating the TVTap IPTV app. It blocks Google Play Protect via a local VPN tunnel, injects phishing overlays across 30+ banking apps primarily in Italy and France, and streams the victim's screen live over WebSocket while an operator drives full remote input.

How RemControl Android Banking Trojan Targets Italy and France works

RemControl is an Android banking trojan first surfaced on VirusTotal on July 19, 2026, distributed via geofenced fake Google Play Store landing pages (localized in Italian, gated by User-Agent and IP geolocation to serve the malicious APK only to Italian mobile IPs) impersonating the TVTap IPTV application, plus Meta Pixel-tracked malvertising (pixel IDs 997470916598588 and 1909605966397328). Distribution domains were registered July 10, 2026, while C2 infrastructure (bnbnhura[.]top) traces back to May 12, 2026, indicating roughly two months of infrastructure staging before public samples appeared.

The dropper abuses the BIND_VPN_SERVICE permission to launch a local VPN tunnel that blocks Google Play Protect from scanning or flagging the payload, and generates a fresh Android Keystore signing key for every installation so that no two installs share a certificate hash, defeating hash-based AV/EDR detection. Strings are obfuscated with Base64 plus XOR.

Once installed, the payload abuses Android's Accessibility Service to inject full-screen phishing overlays over 30+ targeted banking apps, log all keystrokes and UI events, extract pattern-lock grid coordinates across ten OEM Android implementations, and stream the victim's live screen to the operator as WebP frames over WebSocket alongside a JSON serialization of the full accessibility UI tree. The operator can inject taps, swipes, text, and gestures directly, giving VNC-style hands-on-keyboard control of the compromised device. A self-preservation routine watches Accessibility Service navigation events (in 30+ languages) for app-management, accessibility-settings, or factory-reset screens and auto-dismisses them before the victim can act.

Command and control is resolved dynamically through Telegram dead-drop channels (telegram.me/ftestera and a private invite link), with channel content encrypted via AES-128-CBC using SHA-256 marker-derived keys, avoiding hardcoded infrastructure that would require recompilation if seized. The resolved C2 proxy (bnbnhura[.]top) is a FastAPI backend fronted by Cloudflare; the human operator panel is hosted separately at definatelynoone[.]com / 157.90.179.116.

Every analyzed sample carries a hardcoded affiliate tag, UNKK. Group-IB assesses a possible link to the Medusa Android banking botnet's UNKN affiliate program: identical dropper naming convention (instal*tvtap*.apk), shared use of Telegram dead-drop C2 resolution, overlapping Italy/France targeting, a one-character difference between the UNKK and UNKN tags, and Medusa's own distribution activity ceasing around the same period (~July 2026) RemControl appeared. Independent prior reporting on Medusa (Cleafy, PolySwarm, The Hacker News) confirms the UNKN botnet's use of Telegram/X dead-drop resolvers and Accessibility Service abuse against European banking targets, which is consistent with but does not itself confirm the RemControl link. Developer artifacts recovered from the phishing kit (Russian-language HTML comments in the overlay pages; Photoshop asset metadata showing UTC+8 authoring timezone and April 2026 creation dates) provide only circumstantial signal on operator origin and are not treated as confirmed attribution.

Confirmed phishing-overlay targeting spans more than 30 banking apps across Italy (primary, tags IT-NEW/IT-NEW4), France (primary, tags FR-NEW/FR-NEW4), Spain, Poland, Portugal (tag pt-v3), Canada, and GCC member states (tags ARABIC2/ARABIC3).

MITRE ATT&CK techniques used in TL-2026-2625

Defense Evasion

T1406 Obfuscated Files or Information; T1627 Execution Guardrails; T1627.001 Geofencing; T1629 Impair Defenses; T1629.003 Disable or Modify Tools; T1655 Masquerading; T1655.001 Match Legitimate Name or Location

Credential Access

T1417.001 Keylogging; T1417.002 GUI Input Capture

Discovery

T1418 Software Discovery

command-and-control

T1481.001 Dead Drop Resolver; T1521 Encrypted Channel; T1637 Dynamic Resolution

Collection

T1513 Screen Capture

Impact

T1516 Input Injection; T1657 Financial Theft

Exfiltration

T1646 Exfiltration Over C2 Channel

Initial Access

T1660 Phishing

Affected products and versions in RemControl Android Banking Trojan Targets Italy and France

  • Google — Android OS (devices permitting sideloaded/unofficial APK installs)
    Vulnerable versions: Devices with 'install from unknown sources' enabled
  • Multiple financial institutions — Mobile banking applications (30+ targeted via phishing overlay, primarily Italy and France)
    Vulnerable versions: N/A - malware campaign against end-user devices, not a vendor product vulnerability

Remediation for RemControl Android Banking Trojan Targets Italy and France

Immediate actions

  • Block the confirmed distribution and C2 domains/IPs at DNS, proxy, and perimeter firewall: tvtap-hd.app, tvtap-liveapp.com, vpn.doneplay.site, ff-de.shutgpt.ir, vpn.askarzadeh.com, cdn.dlmafi.top, bnbnhura.top, definatelynoone.com, 216.126.229.216, 157.90.179.116
  • Alert on any APK install requesting BIND_VPN_SERVICE and ACCESSIBILITY_SERVICE together from outside the Play Store, especially packages referencing TVTap/IPTV branding
  • Warn banking customers in Italy, France, Spain, Poland, Portugal, Canada, and GCC states against sideloading IPTV/streaming apps from ad links or unofficial Play Store-styled pages

Workarounds

  • Disable the 'Install unknown apps' permission for browsers and messaging apps on Android devices
  • Restrict Accessibility Service grants via device policy to an allow-list of system-verified applications

Longer-term hardening

  • Deploy mobile threat defense (MTD) / enterprise mobility management policy blocking installation from unknown sources and unauthorized Accessibility Service grants on managed devices
  • Implement banking-app runtime overlay and screen-capture detection (RASP) to flag foreign overlay windows, unauthorized Accessibility node access, and screen-streaming behavior
  • Add mobile EDR detection logic for Telegram-based dead-drop C2 resolution patterns and per-install certificate rotation as evasion signals

Timeline of RemControl Android Banking Trojan Targets Italy and France

  • Photoshop metadata embedded in phishing-overlay assets shows creation dates in April 2026 with a UTC+8 authoring timezone, indicating the phishing kit was in development at least five months before public samples appeared.
  • The C2 proxy domain bnbnhura[.]top is registered, marking the earliest observed RemControl operational infrastructure.
  • Distribution of the Medusa/UNKN Android banking botnet, which shares dropper naming, Telegram dead-drop C2 resolution, and Italy/France targeting with RemControl, ceases around this period.
  • Fake TVTap IPTV distribution domains (tvtap-hd[.]app and related infrastructure) are registered.
  • First RemControl dropper and payload samples appear on VirusTotal, marking the earliest confirmed in-the-wild activity.
  • Group-IB publishes technical analysis of RemControl, disclosing distribution mechanism, capabilities, IOCs, and the possible UNKK/UNKN Medusa affiliate link.

Sources cited for RemControl Android Banking Trojan Targets Italy and France

More in malware

Detection coverage for TL-2026-2625

As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2625 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats