Skip to main content

Share story

Security

RemControl Android malware uses fake app pages to steal banking credentials

RemControl Android malware uses fake app pages to steal banking credentials Image: Primary
Cybersecurity researchers at Group-IB have identified RemControl, an Android malware service distributed through fake Google Play pages impersonating the TVTap app. The researchers say it targets users in parts of Europe, Canada and the Middle East. Samples observed in July carried more than 30 overlays designed to imitate banking screens and capture credentials. If a user grants Android accessibility permissions, the malware can read on-screen content and input, display credential prompts over legitimate banking apps, and let an operator perform taps and gestures remotely. Its installer also starts a VPN service that blocks Google Play services traffic, interfering with real-time Play Protect checks. The operator's identity remains unclear.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products
Products

Bird.com raises $450 million in JPMorgan-led debt financing

Bird.com, a customer messaging company, raised $450 million in debt financing led by JPMorgan Chase & Co., Bloomberg reported. The company is seeking to return cash to its investors and employees. The transaction adds debt capital...

Capital Infrastructure
Capital Infrastructure

Hubble Network raises $200 million for satellite Bluetooth network

Satellite startup Hubble Network raised $200 million in a new funding round, Bloomberg reported, taking its valuation to $1.6 billion. The company is working on a network of spacecraft intended to provide global Bluetooth connecti...

Security Infrastructure
Security Infrastructure

CISA adds two exploited Check Point flaws to federal fix list

The U.S. Cybersecurity and Infrastructure Security Agency added two Check Point Security Gateway flaws to its list of known exploited vulnerabilities and told federal agencies to apply fixes or mitigations by September 25. Check P...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...