The Fake TV App That Can Watch Your Screen, Steal Your PIN and Stop You Removing It
The app promises free television. What it installs can watch the screen, read the interface, steal banking credentials, reconstruct a phone’s unlock pattern and push the user out of the very settings needed to remove it.
Group-IB has documented a previously unknown Android banking trojan called RemControl. The malware is distributed through fake Google Play pages impersonating the TVTap IPTV app. Researchers found more than 30 active banking overlays aimed at customers in Italy, France, Spain, Poland, Portugal, Canada and several Gulf states.
This is not a malicious app that slipped through the official Play Store. Group-IB reports that TVTap is not normally available there, so users may already expect to install it from an external website. One observed Italian campaign used mobile browser checks and geofencing to show the malicious download only to selected visitors.
The first target is Google Play Protect
Group-IB found that RemControl’s dropper starts a local VPN service and blocks network traffic from the Google Play Store application. The researchers say this prevents Play Protect from performing its real-time check during installation.
The dropper then generates a fresh signing certificate for each installation before installing the payload. That makes simple certificate and file-hash matching less useful because two victims can receive functionally related malware signed with different keys.
The payload immediately asks for Android Accessibility Service permission. If the user grants it, RemControl gains the visibility and interaction controls that drive most of the attack.
The malware does not need to imitate every bank in advance
Group-IB observed RemControl monitoring which application is in the foreground. When it recognises a targeted banking app, it places a full-screen web overlay above the legitimate interface. That page can collect login details, PINs, card expiry dates and mobile banking codes before disappearing and returning the victim to the genuine app.
The target list is delivered by the command-and-control service after infection. An operator can therefore add or change the banks shown to an infected device without distributing a new app.
The same Accessibility permission supports far more than overlays. Group-IB observed screen capture, streaming of the complete Android interface tree, logging of text and clicks, and remote taps, swipes, scrolling and text entry. The malware also looks for lock-screen components used by Samsung, Xiaomi, Huawei, OPPO, OnePlus and standard Android builds so that it can reconstruct pattern-lock coordinates.
Trying to remove it becomes part of the fight
RemControl watches for attempts to open application management, Accessibility settings or factory-reset controls. When it recognises those screens, it can issue a back action and force the user away. Its removal-blocking strings cover more than 30 languages.
The command server is not fixed inside the app. Group-IB found that RemControl retrieves an encrypted address from Telegram, allowing the operator to redirect infected devices to replacement infrastructure without rebuilding the malware.
Group-IB found exposed API documentation on the criminal infrastructure. It showed affiliate tracking, overlay management and build features consistent with a malware-as-a-service operation. The researchers track the first observed operator as UNKK and identified similarities with a Medusa banking-malware affiliate, but they did not establish a definitive connection.
AI left its fingerprints in the phishing pages
The research also found signs of AI-assisted development. One live banking overlay contained an entire assistant response, including implementation notes and an offer to make further changes. The criminal API documentation described stolen banking details as quiz answers and remote-control features as parental monitoring, suggesting that at least part of the system may have been built by giving an AI tool a false cover story.
That does not mean an AI system independently designed or operated the campaign. The evidence shows AI-assisted development artefacts inside malware infrastructure controlled by people. The important operational effect is lower development friction, not machine autonomy.
What banks, employers and Android users should do
- Keep installation policy simple. Users should obtain apps through the official store unless a documented business need and trusted publisher justify another source.
- Treat unexpected Accessibility requests as a security decision. A television app does not need the ability to read every interface element, press buttons or enter text.
- Detect the installation chain. Mobile-security teams should look for sideloaded TVTap-themed packages, local VPN use that isolates Google Play services, unusual Accessibility grants and Telegram-based command resolution.
- Respond from a second trusted device. When banking credentials may have been captured, contact the bank through a known number and change relevant credentials from a clean system. Do not rely on the infected phone to confirm that containment worked.
- Escalate removal resistance. If the phone repeatedly closes security settings, disconnect it from networks and follow an organisation-approved recovery or reset process. Preserve evidence first when fraud or a wider compromise is suspected.
- Warn exposed financial customers. Banks in the named regions should use the published indicators and observed lure pattern in fraud monitoring, customer communications and takedown work.
BlackTree previously covered Android malware that combined surveillance with device lockout. RemControl shows the same defensive problem from a banking angle: once an app has Accessibility control, the distinction between what the user can see and what the attacker can do becomes dangerously thin.
The reassuring message on the download page is part of the attack. The real security boundary is not whether an app looks familiar. It is whether the phone is being asked to grant a television player the power to operate everything else.
Sources
- Group-IB, RemControl technical investigation, published 23 September 2026. The page provides no publication time.
- BleepingComputer, independent reporting on RemControl, published 23 September 2026 at 17:25 as displayed. The page does not label the timezone.


