RemControl Android Trojan Hijacks Mobile Banking Sessions

The RemControl banking trojan has targeted customers of more than 30 financial institutions across Western Europe, the Middle East, and Canada since July 2026. Distributed through fake Google Play pages impersonating TVTap, the malware suppresses Play Protect checks and requests Accessibility Service permissions to gain extensive control of infected devices. RemControl uses banking overlays, screen capture, keylogging, and pattern-lock monitoring to steal PINs, authentication codes, card details, and other credentials, while blocking removal attempts. Android users should install apps only from official stores, avoid suspicious links, and reject unexpected Accessibility Service requests.

Reference: infosecurity-magazine.com