RemControl Android MaaS malvertising-delivered credential theft platform
Malware Activity
Summary
Hide ▲
Show ▼
RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scalable path to banking credential theft. The infrastructure has been active since at least May, and the first samples were seen in July. The malware uses more than 30 phishing overlays and targets users across Europe, Canada, and the Middle East. It can abuse Accessibility Service permissions, block Google Play services, and stream device data back to operators.
Related Happenings
UNKK RemControl TVTap IPTV malvertising campaign
Campaign
H score35
First: 24.09.2026 00:25
Last: 24.09.2026 00:25
Sources 1
How related:
RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.
About this happening:
A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation m...
UNKK RemControl TVTap IPTV malvertising campaign
CampaignHow related: RemControl is distributed through fake Google Play pages impersonating the TVTap IPTV app, with at least one Italian campaign using geofencing and mobile User-Agent checks.
About this happening: A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation m...
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
StreamRat Android banking trojan with remote-control capabilities
Malware Activity
H score42
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
About this happening:
StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
StreamRat Android banking trojan with remote-control capabilities
Malware ActivityAbout this happening: StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
H score29
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware ActivityAbout this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Timeline
-
24.09.2026 00:25 2 articles · 1h ago
RemControl Android malware campaigns impersonate TVTap IPTV
Initial DisclosureRemControl, an Android malware-as-a-service platform, is distributed through malvertising and fake Google Play pages impersonating the TVTap IPTV app. Group-IB says the infrastructure has been active since at least May, the first samples were observed in July, and those samples contained more than 30 phishing overlays designed to steal banking credentials. The malware targets users in Europe, Canada, and the Middle East, and at least one Italian campaign used geofencing and mobile User-Agent checks.
Show sources
- New RemControl Android banking malware targets users in Europe and Canada — www.bleepingcomputer.com — 24.09.2026 00:25
- New RemControl Android banking malware targets users in Europe and Canada — www.bleepingcomputer.com — 24.09.2026 00:25