{
  "id": 9546755,
  "title": "RemControl: Android Banking Trojan Uses AI-Assisted Overlays and a Local VPN",
  "url": "https://urgent.news/2026/09/24/remcontrol-android-banking-trojan-uses-ai-assisted-overlays-and-a",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T11:26:36.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/remcontrol-android-banking-trojan-uses-ai-assisted-overlays-and-a-local-vpn-2imh"
  },
  "original_language": "en",
  "account": "RemControl is an Android banking trojan that utilizes AI-generated overlays and a local VPN to steal user credentials and gain remote control of infected devices. Discovered in September 2026, this malware targets over 30 financial and cryptocurrency services, with campaigns primarily aimed at users in Europe, the Middle East, and Canada. The malware's dropper employs a fake Google Play page to distribute the APK, which prompts the user to install a VPN to bypass Play Protect checks. Once installed, the malware requests Accessibility Service permissions, allowing it to monitor the screen, perform remote gestures, and input text. The trojan then retrieves the command and control (C2) connection destination from encrypted data on Telegram and communicates using WebSocket as the primary channel and HTTP as a backup. When a target app matches the victim's foreground app, RemControl displays a fake banking screen to collect input data. High visibility is limited to victims, while administrators and SOCs may detect the malware through low visibility signs such as APKs signed with unrecognized certificates, granted Accessibility permissions, and persistent WebSocket traffic. To mitigate RemControl, organizations should block app installations from unknown sources, limit Accessibility permissions, block unauthorized apps and APKs signed with unrecognized certificates via mobile device management (MDM), and investigate unauthorized WebSocket connections.",
  "summary": "+09:00 Source: Group-IB Severity: high Type: Threat Intelligence Target Period: 2026-09-23T08:14:06+09:00 to 2026-09-24T08:09:37+09:00 (Asia/Tokyo) Original Link: RemControl: AI Built the Overlays. Victims Lose their PINs…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}