New Android Banking Trojan Uses AI-Built Overlays to Steal Users’ Banking PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A new Android banking trojan is turning an app download into a banking PIN trap. Called RemControl, it hides behind fake download pages for a television streaming app, then waits for banking apps to open.

The campaign uses pages that look like Google Play listings, even though the streaming app is not offered there.

In one Italian campaign, the pages delivered the malicious installer only to Android visitors with Italian IP addresses, hiding the trap from others. Researchers from Group-IB identified RemControl and traced its activity to samples first seen in July 2026.

Group-IB said in a report shared with Cyber Security News (CSN) that more than 30 banking institutions across Europe, the Middle East and Canada have matching phishing screens.

Fake Google Play phishing page (in Italian) (Source - Group-IB)
Fake Google Play phishing page (in Italian) (Source – Group-IB)

No victim count is confirmed; while the Italy and France were the main targets observed. The discovery adds to concerns about fake streaming app downloads used to place powerful malware on phones.

RemControl goes further than stealing a login: it can watch the screen, record input and let an operator control an infected device remotely.

New Android Banking Trojan Uses AI-Built Overlays

When a targeted banking app opens, RemControl places a full-screen copy of a bank interface over it. The victim may type a PIN, mobile banking code or card expiry date into the imitation. Once the details are submitted, the fake screen closes and the genuine app reappears.

The fake pages arrive from an attacker-controlled server rather than being stored in the installed app. That lets operators change targets without asking victims to install another file. It resembles the technique used by other Android banking trojans that position false screens over trusted apps.

Startup screen of the RemControl dropper (Source - Group-IB)
Startup screen of the RemControl dropper (Source – Group-IB)

The unusual detail is AI-assisted development. Investigators found server documentation describing stolen banking details as quiz answers and remote access as parental monitoring. A complete AI assistant reply, including notes and an offer to make more, had been left inside a live phishing page.

Those clues suggest an AI assistant helped build parts of the criminal platform under a misleading description of its purpose. That does not mean the malware uses AI on the phone. The immediate danger is still the convincing screen that asks for sensitive details at the wrong moment.

Installation and Remote Control

The installer first shows a false streaming app update screen. It then asks for VPN permission and uses a local connection to cut off network traffic from the Play Store during installation, interfering with real-time security checks.

Each installation receives a newly generated signing certificate, complicating detection based on previously seen files. After installation, the trojan asks for Android Accessibility access.

It lets malware read the screen, capture screenshots and make taps or swipes for the operator. Similar permission abuse is described in reporting on Perseus banking malware campaigns that also used fake streaming apps.

RemControl can log typed text and inspect a device’s on-screen controls while streaming screenshots. It can also gather information needed to reconstruct an unlock pattern and push users out of settings screens when they try to remove it. These features make the risk broader than a single stolen banking PIN.

The dropper asks the victim for permission to install other apps (Source - Group-IB)
The dropper asks the victim for permission to install other apps (Source – Group-IB)

The operation resembles a service for other criminals. An exposed control panel offered tools for creating app builds, managing infected devices and viewing captured credentials.

Investigators linked the observed samples to an affiliate label, UNKK, but described a possible connection to another banking malware network as unproven.

The malware fetches its server location through Telegram, allowing operators to change where infected phones connect without rebuilding the app.

Updated overlays help the campaign shift targets. It follows a wider pattern of banking PIN theft attempts that combine deceptive screens with remote phone control.

Users should avoid app downloads offered through links or unfamiliar websites, even when a page resembles an official store.

Review unexpected VPN and Accessibility requests, and never enter banking details into a screen that appears without warning. Anyone who suspects account misuse should contact their bank through official channels.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps[:]//tvtap-hd[.]app/ Fake TVTap download website
URL hxxp[:]//vpn[.]doneplay[.]site/ Fake TVTap download website
URL hxxp[:]//ff-de[.]shutgpt[.]ir/ Fake TVTap download website
URL hxxp[:]//vpn[.]askarzadeh[.]com/ Fake TVTap download website
URL hxxp[:]//cdn[.]dlmafi[.]top/ Fake TVTap download website
URL hxxp[:]//216[.]126[.]229[.]216/ Fake TVTap download website
URL hxxps[:]//tvtap-liveapp[.]com/dl.php Final download URL
URL hxxps[:]//telegram[.]me/ftestera Telegram dead-drop
URL hxxps[:]//telegram[.]me/+Psyt04xu-cRjMTg0 Telegram dead-drop
Domain bnbnhura[.]top RemControl proxy server
URL hxxps[:]//definatelynoone[.]com Operator panel
URL hxxps[:]//157[.]90[.]179[.]116 Operator panel
Tracking ID 997470916598588 Meta Pixel ID embedded in distribution pages
Tracking ID 1909605966397328 Meta Pixel ID embedded in distribution pages
File name pattern instal*tvtap*.apk Dropper naming convention noted in the investigation
Configuration marker numeraZZZas Marker used to decode the server address
SHA-256 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b Dropper
SHA-256 fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e Dropper
SHA-256 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 Dropper
SHA-256 dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 Dropper
SHA-256 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb Dropper
SHA-256 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 Dropper
SHA-256 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d Dropper
SHA-256 cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 Dropper
SHA-256 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 Dropper
SHA-256 af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c Payload
SHA-256 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c Payload
SHA-256 c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 Payload
SHA-256 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f Payload
SHA-256 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a Payload
SHA-256 ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f Payload
SHA-256 b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 Payload
SHA-256 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 Payload
SHA-256 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 Payload

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post New Android Banking Trojan Uses AI-Built Overlays to Steal Users’ Banking PINs appeared first on Cyber Security News.