RemControl: AI Built the Overlays. Victims Lose their PINs

    Date: 09/24/2026

    Severity: Medium

    Summary

    RemControl is a previously undocumented Android banking trojan targeting retail banking customers across Western Europe, the Middle East, and Canada. It abuses Android Accessibility Services to display fake banking overlays, capture PINs and keystrokes, stream screens, and provide attackers with full remote control. The malware is distributed through fake Google Play pages and malvertising, while its MaaS infrastructure uses Telegram dead-drops, affiliate tracking, and dynamic C2. Researchers also found strong evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing overlay.   

    Indicators of Compromise (IOC) List

    Domains/URLs

    https://tvtap-hd.app/

    http://vpn.doneplay.site/

    http://ff-de.shutgpt.ir/

    http://vpn.askarzadeh.com/

    http://cdn.dlmafi.top/

    http://216.126.229.216/

    https://tvtap-liveapp.com/dl.php

    https://telegram.me/ftestera

    https://telegram.me/+Psyt04xu-cRjMTg0

    bnbnhura.top

    https://definatelynoone.com

    https://157.90.179.116

    Hash

    76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b

    fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e

    45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1

    dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730

    3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb

    19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1

    54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d

    cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889

    1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7

    af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c

    28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c

    c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0

    95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f

    77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a

    ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f

    b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3

    648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1

    5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection        

    Detection Query 1 :

    domainname like "http://vpn.doneplay.site/" or url like "http://vpn.doneplay.site/" or siteurl like "http://vpn.doneplay.site/" or domainname like "http://216.126.229.216/" or url like "http://216.126.229.216/" or siteurl like "http://216.126.229.216/" or domainname like "https://definatelynoone.com" or url like "https://definatelynoone.com" or siteurl like "https://definatelynoone.com" or domainname like "http://vpn.askarzadeh.com/" or url like "http://vpn.askarzadeh.com/" or siteurl like "http://vpn.askarzadeh.com/" or domainname like "http://ff-de.shutgpt.ir/" or url like "http://ff-de.shutgpt.ir/" or siteurl like "http://ff-de.shutgpt.ir/" or domainname like "https://tvtap-liveapp.com/dl.php" or url like "https://tvtap-liveapp.com/dl.php" or siteurl like "https://tvtap-liveapp.com/dl.php" or domainname like "https://tvtap-hd.app/" or url like "https://tvtap-hd.app/" or siteurl like "https://tvtap-hd.app/" or domainname like "bnbnhura.top" or url like "bnbnhura.top" or siteurl like "bnbnhura.top" or domainname like "https://telegram.me/+Psyt04xu-cRjMTg0" or url like "https://telegram.me/+Psyt04xu-cRjMTg0" or siteurl like "https://telegram.me/+Psyt04xu-cRjMTg0" or domainname like "http://cdn.dlmafi.top/" or url like "http://cdn.dlmafi.top/" or siteurl like "http://cdn.dlmafi.top/" or domainname like "https://157.90.179.116" or url like "https://157.90.179.116" or siteurl like "https://157.90.179.116" or domainname like "https://telegram.me/ftestera" or url like "https://telegram.me/ftestera" or siteurl like "https://telegram.me/ftestera"

    Detection Query 2 :

    sha256hash IN ("19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1","cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889","b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3","648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1","c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0","77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a","3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb","76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b","fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e","54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d","dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730","45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1","1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7","af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c","28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c","ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f","95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f","5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4")

    Reference: 

    https://www.group-ib.com/blog/remcontrol-android-banking-trojan/


    Tags

    MalwareAndroid MalwareTrojanFinancial ServicesEuropeThe Middle EastCanadaMaaSTelegramAI

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags