Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNKK RemControl TVTap IPTV malvertising campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation matters because it combines geofencing, mobile User-Agent checks, and phishing overlays to narrow delivery to specific regions and hide the abuse. The campaign is linked to the tracked operator UNKK and has been active since at least May.

Related Happenings

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity
H score29 First: 24.09.2026 00:25 Last: 24.09.2026 00:25 Sources 1

How related: A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.

About this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...

StreamRat Android banking trojan with remote-control capabilities

Malware Activity
H score42 First: 02.09.2026 15:22 Last: 02.09.2026 15:22 Sources 1

About this happening: StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

Sniper Dz MENA fake Facebook phishing and monetization campaign

Campaign
H score30 First: 15.06.2026 09:30 Last: 15.06.2026 09:30 Sources 1

About this happening: A Sniper Dz fraud campaign is targeting users across the Middle East and North Africa with fake Facebook accounts that impersonate politicians, public figures, and tru...

Timeline

  1. 24.09.2026 00:25 2 articles · 1h ago

    RemControl malvertising campaign impersonates TVTap IPTV

    Initial Disclosure

    Group-IB described a new Android malware-as-a-service platform called RemControl that uses malvertising to impersonate the TVTap IPTV app through fake Google Play pages. The campaign has been active since at least May, first samples were observed in July with more than 30 phishing overlays designed to steal banking credentials, and at least one Italian campaign used geofencing and mobile User-Agent checks. The operation targets Android users in Europe, Canada, and countries in the Middle East, and the operator is tracked as UNKK.

    Show sources