UNKK RemControl TVTap IPTV malvertising campaign
Campaign
Summary
Hide ▲
Show ▼
A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation matters because it combines geofencing, mobile User-Agent checks, and phishing overlays to narrow delivery to specific regions and hide the abuse. The campaign is linked to the tracked operator UNKK and has been active since at least May.
Related Happenings
RemControl Android MaaS malvertising-delivered credential theft platform
Malware Activity
H score29
First: 24.09.2026 00:25
Last: 24.09.2026 00:25
Sources 1
How related:
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
About this happening:
RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
RemControl Android MaaS malvertising-delivered credential theft platform
Malware ActivityHow related: A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
About this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
StreamRat Android banking trojan with remote-control capabilities
Malware Activity
H score42
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
About this happening:
StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
StreamRat Android banking trojan with remote-control capabilities
Malware ActivityAbout this happening: StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Sniper Dz MENA fake Facebook phishing and monetization campaign
Campaign
H score30
First: 15.06.2026 09:30
Last: 15.06.2026 09:30
Sources 1
About this happening:
A Sniper Dz fraud campaign is targeting users across the Middle East and North Africa with fake Facebook accounts that impersonate politicians, public figures, and tru...
Sniper Dz MENA fake Facebook phishing and monetization campaign
CampaignAbout this happening: A Sniper Dz fraud campaign is targeting users across the Middle East and North Africa with fake Facebook accounts that impersonate politicians, public figures, and tru...
Timeline
-
24.09.2026 00:25 2 articles · 1h ago
RemControl malvertising campaign impersonates TVTap IPTV
Initial DisclosureGroup-IB described a new Android malware-as-a-service platform called RemControl that uses malvertising to impersonate the TVTap IPTV app through fake Google Play pages. The campaign has been active since at least May, first samples were observed in July with more than 30 phishing overlays designed to steal banking credentials, and at least one Italian campaign used geofencing and mobile User-Agent checks. The operation targets Android users in Europe, Canada, and countries in the Middle East, and the operator is tracked as UNKK.
Show sources
- New RemControl Android banking malware targets users in Europe and Canada — www.bleepingcomputer.com — 24.09.2026 00:25
- New RemControl Android banking malware targets users in Europe and Canada — www.bleepingcomputer.com — 24.09.2026 00:25