Skip to content
Malware family

Remo

Remo is an Android remote access trojan used in mobile banking fraud campaigns.

Profile source: Mallory opens in a new tab

Remo

Family profile

Remo is an Android remote access trojan used in mobile banking fraud campaigns. The provided content links it to GoldFactory, a financially motivated Chinese-speaking cybercrime group targeting users in Indonesia, Thailand, and Vietnam since at least October 2024. In these campaigns, attackers impersonate government services and use phone calls, messaging apps, and fake Google Play Store landing pages to trick victims into installing trojanized or modified banking applications. Remo is described as being deployed alongside other Android RATs such as Gigabud and MMRat.

High-confidence reporting in the content also identifies Remo as Android.BankBot.Remo.1.origin and states that it abuses Android Accessibility Services to steal data from banking applications and cryptocurrency wallets. The broader GoldFactory tradecraft described in the content indicates that malware in this campaign is injected into legitimate banking apps while preserving normal app functionality, and uses runtime-hooking frameworks such as Frida, Dobby, and Pine to bypass security controls and conceal malicious behavior. Reported capabilities associated with these modified-app campaigns include remote control via accessibility abuse, hiding accessibility-enabled apps, preventing screencast detection, spoofing app signatures, hiding installation sources, implementing custom integrity tokens, and obtaining account balances.

The content does not provide specific standalone indicators of compromise for Remo such as hashes, package names, domains, or C2 infrastructure.

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 23, 2026
Feed role
C2
Host form
0 IP / 4 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
GoldFactory

...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.