$ techbeacon▋
Phishing

RemControl Android Trojan Hijacks Banking Apps Across Europe, Middle East and Canada

RemControl Android Trojan Hijacks Banking Apps Across Europe, Middle East and Canada

Security analysts have uncovered a new Android banking trojan, dubbed RemControl, that is actively siphoning login credentials and personal identification numbers from users of more than 30 financial institutions in Europe, the Middle East and Canada.

The malicious software is distributed through counterfeit listings on the Google Play Store, where it masquerades as legitimate applications. Once installed, RemControl exploits Android's Accessibility Service to gain deep system privileges, allowing it to overlay fake input fields on top of genuine banking apps and capture users' PINs and passwords as they type.

Researchers say the trojan’s modular design lets cyber‑criminals quickly add new target banks to its roster, expanding its reach as quickly as new counterfeit app pages appear. The use of overlay screens is a technique that has grown popular among mobile banking malware because it can bypass two‑factor authentication prompts that rely on on‑screen entry.

The campaign’s geographic spread reflects the global popularity of Android devices for mobile banking. While the affected institutions have not been publicly named, the breadth of the attack suggests that the perpetrators are focusing on banks with large consumer bases in regions where mobile banking adoption is high.

Security experts warn that users should verify the authenticity of app listings by checking developer credentials, download counts, and reviews before installing any banking application. Enabling two‑factor authentication that relies on out‑of‑band methods, such as hardware tokens or SMS codes, can also mitigate the risk of credential capture through screen overlays.

Google has been notified of the fraudulent listings and is expected to remove the offending pages, though the speed of takedown can vary. In the meantime, mobile security firms recommend that users keep their devices updated, restrict Accessibility Service permissions to only trusted apps, and consider installing reputable mobile security solutions that can detect known malware signatures.

The discovery, first reported by the cybersecurity community GBHackers, underscores the ongoing challenge of securing mobile banking ecosystems against increasingly sophisticated threats. As attackers refine their techniques, financial institutions and platform providers are likely to intensify collaboration on threat intelligence sharing and rapid response mechanisms to protect consumers.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related