UNKK
❔ UnknownLast active: 2026-09-23First seen: 2026-09-23
0
linked CVEs
Targeted industries
Finance
Targeted regions
CanadaFranceItalyPolandPortugalSpain
Group-IB researchers discovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service since May 2026. The malware targets over 30 financial institutions across Western Europe, the Middle East, and Canada through fake TVTap IPTV download pages distributed via malvertising. RemControl abuses Android Accessibility Service to inject phishing overlays, stream device screens in real-time, log keystrokes, and provide full remote control. The investigation revealed that the criminal infrastructure was inadvertently built using AI assistance, with complete AI-generated responses found verbatim in production phishing pages. The C2 panel documentation describes credential theft as quiz completion, suggesting developers deceived AI assistants into building fraud infrastructure under false pretenses. The threat actor UNKK operates the campaigns, with possible links to the Medusa UNKN affiliate botnet based on overlapping infrastructure patterns and naming conventions.
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs28
| sha256 | 54efee2665d3779f1be0d885409e29e6cd07fe944fa82e5d6eeb832264c7409d | — | 2026-09-23 |
| sha256 | c6e1235d5cd01a205a191ce48c3d68e9fea620671c0c069593027a0218fad5b0 | — | 2026-09-23 |
| sha256 | 28a09cd68b1f4212cc61bd2d44d03d55b8bcd7df284bab56cdae8507abc90e3c | — | 2026-09-23 |
| sha256 | cb29b6348ae4458b6b506f8de9336d0980bbfaf88b1d68be2771b57090d29889 | — | 2026-09-23 |
| sha256 | af2decf5c5cbff0c0460ab09ad3cff497c765e3cf61e6c45f4e3b5c6a103312c | — | 2026-09-23 |
| sha256 | 19fef425c3a774e493526126a441a31971db8ac5af84c1d9eef15a272ba02ec1 | — | 2026-09-23 |
| sha256 | b714f590380e5be8233cd60a4f212d949aff27b3a980e6d644c84b0120dd25b3 | — | 2026-09-23 |
| sha256 | ad2b019cf346b8b4e6b2174a95b1d897ce736087bd06066f31a9d7fd72283e9f | — | 2026-09-23 |
| sha256 | 45e16e56c81059f6758dced28a58256287785a8b0815577c1140293589aa2ae1 | — | 2026-09-23 |
| domain | ff-de.shutgpt.ir | — | 2026-09-23 |
| domain | cdn.dlmafi.top | — | 2026-09-23 |
| sha256 | fa373aaa95ca512ba9595c3ab41bac892c8c79d4a31f5d74c2f3225b629de52e | — | 2026-09-23 |
| sha1 | b60cee64202c6ad48808c10226093540292ae4b8 | — | 2026-09-23 |
| sha256 | 5fff21af95bd38b8c11dd73342a55acb75e91ff1936ed0ccb06af28400ef87d4 | — | 2026-09-23 |
| domain | tvtap-liveapp.com | — | 2026-09-23 |
| domain | definatelynoone.com | — | 2026-09-23 |
| sha256 | dd6d05ff31f64b9ca8ca9334a804dbee5917d6448acb026de4ca818017a04730 | — | 2026-09-23 |
| sha256 | 1a992e2b36b2a9a77300b0b0fe7e9c20e127c8257fd203bb4b3eaf1e35e63ce7 | — | 2026-09-23 |
| sha256 | 77ead085bae72b6cb1c33c55fbd7763c4d8050798c55af3132c3b904084eeb8a | — | 2026-09-23 |
| md5 | f9e6ea83e50b72a081aef44d22f19bcf | — | 2026-09-23 |
| sha256 | 3b0c49ed1590bceffbefed150bb64545e69e792c5ad63578cc3bca5c5b96f2cb | — | 2026-09-23 |
| sha256 | 648b34fa952a2806d9f4c272f8bfbadc45c0c370c3d7c2ff0c7ffbb015237ce1 | — | 2026-09-23 |
| sha256 | 76392303f28a7e6f1463a5fa04a19faf40d51d7be6619943a914482b0f3c7f0b | — | 2026-09-23 |
| ip | 216.126.229.216 | — | 2026-09-23 |
| domain | vpn.askarzadeh.com | — | 2026-09-23 |
| domain | bnbnhura.top | — | 2026-09-23 |
| sha256 | 95ec481745c64c385c60f6c812585e5060a50e38da44bc1a9f67da3921b1a50f | — | 2026-09-23 |
| domain | vpn.doneplay.site | — | 2026-09-23 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.