# RemControl Android malware uses fake app pages to steal banking credentials

_Published Wednesday, September 23, 2026 at 6:08 PM EDT · Security · Latest · Tier 2 — Notable_

![RemControl Android malware uses fake app pages to steal banking credentials — Primary](https://www.bleepstatic.com/content/hl-images/2024/01/31/image_(2).jpg)

Cybersecurity researchers at Group-IB have identified RemControl, an Android malware service distributed through fake Google Play pages impersonating the TVTap app. The researchers say it targets users in parts of Europe, Canada and the Middle East. Samples observed in July carried more than 30 overlays designed to imitate banking screens and capture credentials.

If a user grants Android accessibility permissions, the malware can read on-screen content and input, display credential prompts over legitimate banking apps, and let an operator perform taps and gestures remotely. Its installer also starts a VPN service that blocks Google Play services traffic, interfering with real-time Play Protect checks. The operator's identity remains unclear.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/)

---
Canonical: https://techandbusiness.org/newswire/lNADept_z11sPXBWs5e8St
Published: 2026-09-23T22:08:33.058Z
Story chronology: 2026-09-23T21:25:13.000Z
Retrieved: 2026-09-23T23:28:47.230Z
Publisher: Tech & Business (techandbusiness.org)
