New Android malware RemControl steals banking PINs and blocks removal attempts

New Android malware RemControl steals banking PINs and blocks removal attempts A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found.
Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada and some Gulf states. The first samples were submitted to VirusTotal on July 19, 2026. The domain used for its command and control (C2) server was registered on May 12, 2026, two months earlier.
“RemControl spreads through fake Google Play Store pages impersonating the TVTap IPTV application. TVTap is a popular third-party IPTV application that is not available on the Google Play Store, making users accustomed to seeking it from unofficial sources. This is why IPTV apps like this are among the most popular lures for Android malware distribution,” Group-IB wrote.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in