$ techbeacon▋
Phishing

New Android Banking Trojan Exploits Accessibility Service to Hijack Devices

New Android Banking Trojan Exploits Accessibility Service to Hijack Devices

A previously unknown Android malware, dubbed RemControl, has been identified as capable of seizing full control of smartphones and harvesting banking credentials by abusing the platform's Accessibility Service.

The malicious code leverages the Accessibility Service, a feature intended to help users with disabilities interact with their devices, to simulate taps, read screen contents, and capture one‑time passwords. Once granted the required permission, the trojan can navigate banking apps, record keystrokes, and exfiltrate the data to remote servers controlled by the attackers.

Security researchers who first uncovered RemControl say the trojan is distributed primarily through third‑party app stores and deceptive links that encourage users to install seemingly harmless utilities. Because the Accessibility Service can be enabled without the stringent permission dialogs that other high‑risk permissions trigger, many victims remain unaware that they have effectively granted a backdoor to their device.

The discovery follows a broader trend of financially motivated Android threats that target the same service. In recent years, several banking trojans have been observed abusing Accessibility to bypass two‑factor authentication and automate fraudulent transactions. Analysts note that the open nature of the Android ecosystem, combined with the growing popularity of mobile banking, creates a fertile environment for such campaigns.

Experts advise users to scrutinize any request for Accessibility access, especially from apps that do not clearly need it for core functionality. Removing unnecessary apps, sticking to official app stores, and regularly reviewing granted permissions are recommended steps to mitigate the risk. Security vendors are also updating their detection signatures to flag the behavior patterns associated with RemControl.

While the full scale of the campaign remains under investigation, the emergence of RemControl underscores the ongoing challenge of balancing accessibility features with robust security controls. Authorities and platform owners are expected to issue guidance on tighter vetting of Accessibility requests, and researchers will continue monitoring for variants that may adopt similar tactics.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related