Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 4 hostnames
Remo is an Android remote access trojan used in mobile banking fraud campaigns.
Profile source: Mallory opens in a new tabRemo
Remo is an Android remote access trojan used in mobile banking fraud campaigns. The provided content links it to GoldFactory, a financially motivated Chinese-speaking cybercrime group targeting users in Indonesia, Thailand, and Vietnam since at least October 2024. In these campaigns, attackers impersonate government services and use phone calls, messaging apps, and fake Google Play Store landing pages to trick victims into installing trojanized or modified banking applications. Remo is described as being deployed alongside other Android RATs such as Gigabud and MMRat.
High-confidence reporting in the content also identifies Remo as Android.BankBot.Remo.1.origin and states that it abuses Android Accessibility Services to steal data from banking applications and cryptocurrency wallets. The broader GoldFactory tradecraft described in the content indicates that malware in this campaign is injected into legitimate banking apps while preserving normal app functionality, and uses runtime-hooking frameworks such as Frida, Dobby, and Pine to bypass security controls and conceal malicious behavior. Reported capabilities associated with these modified-app campaigns include remote control via accessibility abuse, hiding accessibility-enabled apps, preventing screencast detection, spoofing app signatures, hiding installation sources, implementing custom integrity tokens, and obtaining account balances.
The content does not provide specific standalone indicators of compromise for Remo such as hashes, package names, domains, or C2 infrastructure.
Samples
Reported operators
...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.