Remo is an Android banking trojan used to steal data from banking and cryptocurrency wallet applications. It has been observed distributed through phishing infrastructure and fake landing pages impersonating trusted brands, including cryptocurrency services, and in broader Southeast Asian mobile fraud operations that redirected victims to counterfeit app-store style pages. Activity associated with Remo has targeted users in Thailand, Vietnam, Indonesia, and South Korea, with victim focus on dozens of financial and crypto applications.
On infected devices, Remo abuses Android Accessibility services to conduct credential and data theft. Reported behavior includes capturing visible screen text from targeted applications, logging keyboard input, monitoring clipboard contents, collecting device and application metadata, and attempting to harvest contacts. It can also use Accessibility abuse to auto-grant permissions and hinder removal, increasing persistence and resistance to user remediation. Remo communicates with attacker-controlled infrastructure to retrieve target application lists and exfiltrate stolen information.
The malware has been described as heavily obfuscated, using encrypted strings and custom decryption logic to complicate reverse engineering and reduce detection. Code and infrastructure artifacts have included Chinese-language elements, leading to reporting that the operators may be Chinese-speaking, although attribution remains unconfirmed. Remo has also been referenced alongside other Android remote-access malware used in campaigns attributed to GoldFactory, a financially motivated group targeting Southeast Asian mobile users through social engineering, fake banking apps, and counterfeit app distribution workflows. In those operations, victims were lured via phone calls, SMS, or messaging applications and directed to install malicious Android packages from fraudulent pages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan leveraging Accessibility Services to steal data from banking apps and crypto wallets; observed in parts of Southeast Asia/APAC.
Banking trojan leveraging Android Accessibility Services to steal data from banking apps and crypto wallets; observed targeting Southeast Asia/APAC users.
A remote access trojan for Android, distributed via fake banking apps, used for remote control and credential theft.
Android remote access trojan used for remote control and fraud, distributed through impersonation of legitimate services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.