RemControl Trojan Steals Banking Credentials The malicious software targets individuals across Western Europe, the Middle East, and Canada. First detected in July 2026, RemControl is spread through fake Google Play Store pages promoting TVTap, an IPTV app. When installation begins, it launches a local VPN service that blocks network traffic from the Google Play Store app, interfering with real-time Play Protect checks.

It then creates a new signing certificate for the malware payload on each installation, making certificate-based detection more challenging, before installing the payload. The malware can capture screenshots, stream interface structures, log typing events, and remotely perform actions such as tapping, swiping, and typing.

The panel unveiled tools for managing infected devices, editing phishing overlays, recording remote-control sessions, and generating APK builds with affiliate tags. API documentation labeled banking credential submissions as "quiz answers," while one phishing page contained a complete AI assistant response accidentally left in its HTML. These artifacts support AI involvement in building parts of the infrastructure and overlays, but do not indicate that AI independently targeted victims or ran the campaign.

Signs of Compromise Indicator Type Description hxxps[:]//tvtap-hd[. ]app/ URL Fake TVTap download page hxxp[:]//vpn[.]doneplay[. ]site/ URL Fake TVTap download page