New RemControl Android Banking MaaS Targets Users in Europe and Canada
Malvertising campaigns impersonate TVTap IPTV to distribute banking malware
.jpg)
Key Takeaways
- A new Android banking MaaS platform named RemControl has been identified targeting users in Europe and Canada.
- Malvertising campaigns are impersonating the TVTap IPTV application to distribute the malware.
- The malware is designed to steal financial information and credentials from infected devices.
- No patch exists for the malware; users are advised to download applications only from official stores and verify permissions.
- Security researchers are monitoring for new variants and additional distribution methods.
Quick answers
- What happened?
- Security researchers have identified a new Android malware-as-a-service platform named RemControl being used in malvertising campaigns that impersonate the TVTap IPTV application. The campaigns target users in Europe and Canada, aiming to steal financial information and credentials.
- Which products are affected?
- TVTap
- What should defenders do?
- Users should only download applications from official app stores, carefully review application permissions, and avoid sideloading apps from malvertising campaigns. Security researchers recommend vigilance and monitoring for new variants of the RemControl platform. Organizations should educate users about the risks of downloading applications from unofficial sources.
A new Android malware-as-a-service (MaaS) platform called RemControl is being deployed through malvertising campaigns that impersonate the TVTap IPTV application, according to recent analysis. The threat actors behind the campaign are distributing the malware to users in Europe and Canada, tricking them into installing malicious applications under the guise of a legitimate streaming service.
The RemControl platform functions as a MaaS offering, allowing threat actors to lease the malware infrastructure. The campaigns have been observed using malvertising to promote fake TVTap applications, which, once installed, can execute banking-fraud activities such as overlay attacks and credential harvesting. Security researchers note that the malware is designed to steal financial information from affected devices.
As of the reporting date, no specific victim counts or financial impact figures have been disclosed. The full scope of the malvertising distribution network and the exact methods used to lure victims remain under investigation. Security firms including ESET are monitoring the situation for new variants and additional distribution channels.
Security Details
The RemControl malware is distributed via malvertising campaigns that impersonate the TVTap IPTV application. The MaaS model enables threat actors to lease the malware for conducting banking fraud. The malware targets users in Europe and Canada and is designed to steal financial information and credentials. Distribution occurs through deceptive advertising promoting fake streaming applications.
Affected products
TVTap
Mitigation
Users should only download applications from official app stores, carefully review application permissions, and avoid sideloading apps from malvertising campaigns. Security researchers recommend vigilance and monitoring for new variants of the RemControl platform. Organizations should educate users about the risks of downloading applications from unofficial sources.
Sources
BleepingComputer
New RemControl Android banking malware targets users in Europe and Canada
Sep 23, 2026 · 21:25
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




