Find notable cyber news and cases, enriched with sources, timelines, and signals.

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scalable path to banking credential theft. The infrastructure has been active since at least May, and the first samples were seen in July. The malware uses more than 30 phishing overlays and targets users across Europe, Canada, and the Middle East. It can abuse Accessibility Service permissions, block Google Play services, and stream device data back to operators.

Related Happenings

UNKK RemControl TVTap IPTV malvertising campaign

Campaign
H score35 First: 24.09.2026 00:25 Last: 24.09.2026 00:25 Sources 1

How related: RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.

About this happening: A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation m...

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

StreamRat Android banking trojan with remote-control capabilities

Malware Activity
H score42 First: 02.09.2026 15:22 Last: 02.09.2026 15:22 Sources 1

About this happening: StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...

ToxicPanda 2.0 Android malware expands fraud capabilities

Malware Activity
H score29 First: 20.08.2026 13:38 Last: 20.08.2026 13:38 Sources 1

About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...

Manic Android malware activity with offline relay exfiltration

Malware Activity
H score29 First: 20.08.2026 13:02 Last: 20.08.2026 13:02 Sources 1

About this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...

Timeline

  1. 24.09.2026 00:25 2 articles · 1h ago

    RemControl Android malware campaigns impersonate TVTap IPTV

    Initial Disclosure

    RemControl, an Android malware-as-a-service platform, is distributed through malvertising and fake Google Play pages impersonating the TVTap IPTV app. Group-IB says the infrastructure has been active since at least May, the first samples were observed in July, and those samples contained more than 30 phishing overlays designed to steal banking credentials. The malware targets users in Europe, Canada, and the Middle East, and at least one Italian campaign used geofencing and mobile User-Agent checks.

    Show sources