Skip to content

Remo

Remo is an Android banking trojan used to steal data from banking and cryptocurrency wallet applications.

Profile source: Mallory opens in a new tab

Remo

Family profile

Remo is an Android banking trojan used to steal data from banking and cryptocurrency wallet applications. It has been observed distributed through phishing infrastructure and fake landing pages impersonating trusted brands, including cryptocurrency services, and in broader Southeast Asian mobile fraud operations that redirected victims to counterfeit app-store style pages. Activity associated with Remo has targeted users in Thailand, Vietnam, Indonesia, and South Korea, with victim focus on dozens of financial and crypto applications.

On infected devices, Remo abuses Android Accessibility services to conduct credential and data theft. Reported behavior includes capturing visible screen text from targeted applications, logging keyboard input, monitoring clipboard contents, collecting device and application metadata, and attempting to harvest contacts. It can also use Accessibility abuse to auto-grant permissions and hinder removal, increasing persistence and resistance to user remediation. Remo communicates with attacker-controlled infrastructure to retrieve target application lists and exfiltrate stolen information.

The malware has been described as heavily obfuscated, using encrypted strings and custom decryption logic to complicate reverse engineering and reduce detection. Code and infrastructure artifacts have included Chinese-language elements, leading to reporting that the operators may be Chinese-speaking, although attribution remains unconfirmed. Remo has also been referenced alongside other Android remote-access malware used in campaigns attributed to GoldFactory, a financially motivated group targeting Southeast Asian mobile users through social engineering, fake banking apps, and counterfeit app distribution workflows. In those operations, victims were lured via phone calls, SMS, or messaging applications and directed to install malicious Android packages from fraudulent pages.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence

Reported operators

Threat actors

1 named in public reporting
GoldFactory

...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.