The free TV app that watches you type your banking PIN
TVTap is a free IPTV app that has never been on Google Play. People go looking for it elsewhere, which is precisely what makes it good bait.
Group-IB published its analysis this week of RemControl, an Android banking trojan rented out as a service and spread through fake Google Play pages advertising that app. The adverts carry Meta Pixel tracking IDs, which points at paid traffic bought through Meta's ad system. The malware ships with more than 30 phishing overlays aimed at banks in Italy, France, Spain, Poland, Portugal, Canada and the Gulf states. Its command server domain was registered on 12 May and the first samples reached VirusTotal on 19 July.
What it does after installation is the grim part. It asks for Android's accessibility permissions, then uses them to paint a fake login screen over your real banking app and take the PIN, the card expiry date and the one-time codes as you type them. It streams your screen to the operator live, logs keystrokes across every app, and records the coordinates you trace for the lock-screen pattern on Samsung, Xiaomi, Huawei, OPPO and OnePlus handsets. A local VPN service keeps Google Play Protect from phoning home. And when you go hunting for the uninstall button, it blocks the screen, in more than thirty languages.
Group-IB tags the operator UNKK, from an affiliate string in every sample, and suspects a link to the crew behind the Medusa trojan. The lesson underneath all of it is older than any Android phone: a television app has no business asking for accessibility permissions, and a Play Store page you reached from an advert is not the Play Store. Tendvane's network scan at least shows you every device sitting on your home Wi-Fi, phones and all.