Trusted Interfaces Turn Hostile Across Banking, AI, Industrial Systems and Software Updates
Attackers exploit banking apps, AI answers, Google sign-in and ICS access. Learn how RemControl, Z.ai, MAX and fake support scams abuse trusted interfaces.
Illustrative image generated with AI
A series of recent security findings shows attackers exploiting interfaces users and operators are conditioned to trust: banking apps, Google sign-in windows, AI-generated answers, WordPress updates and remote industrial support channels.
The incidents range from active malware campaigns to architectural privacy concerns. They also include an established WinRAR vulnerability, CVE-2023-38831, that remains operationally relevant because it has been exploited in ransomware campaigns.
RemControl takes over Android banking sessions
Group-IB has identified RemControl, a previously undocumented Android banking trojan first observed in July 2026. Its targets include retail banking customers in Italy, France, Spain, Poland and Portugal, alongside users in the Middle East and Canada.
The campaign begins with Meta advertisements that send victims to counterfeit Google Play Store pages impersonating the TVTap IPTV application. Once installed, RemControl abuses Android’s Accessibility Service to interact with the device and monitor the user.
Its capabilities include placing phishing overlays above legitimate banking apps, recording keystrokes, streaming the screen and providing remote control to an operator. Together, those functions can expose login credentials and let an attacker manipulate a live banking session.
RemControl does not rely on a fixed command-and-control address embedded in the application. Instead, it retrieves the current C2 location through an encrypted Telegram dead drop. Operators can therefore move their infrastructure without rebuilding and redistributing the malware.
Group-IB also found signs that artificial intelligence assisted development. Operator documentation and phishing overlays contained AI-like material, including one complete assistant response accidentally left in a page shown to victims. Russian comments in several overlay HTML files suggest involvement by a Russian speaker.
Campaign names, affiliate tags, distribution methods and Telegram use resemble the Medusa UNKN affiliate botnet. The connection remains possible, not confirmed.
Android users should avoid installing applications from pages reached through advertisements, even when those pages reproduce Google Play branding. Unexpected Accessibility Service requests are particularly significant because that permission can expose screen content and enable automated interaction.
AI tools expose code and poison support searches
Chinese AI company Z.ai disabled several ZCode features after researchers found that its default configuration sent snapshots of local code repositories to Alibaba Cloud infrastructure in China without user consent. The company stopped the snapshot-generation and upload workflow and released the assistant’s codebase for public examination.
The incident follows an earlier finding involving SpaceXAI’s Grok Build command-line coding tool. That product uploaded complete Git repositories to a Google Cloud Storage bucket controlled by its operator.
For enterprises, the problem extends beyond source files. Repositories can contain internal documentation, configuration data, development history and other sensitive material. Organizations evaluating coding assistants need to establish what data leaves developer systems, where it is stored and whether collection is enabled by default.
A separate campaign reported by Vigilance Security researcher Ariel Simon targets the information returned by ChatGPT, Gemini and Google AI Overviews. Attackers publish search-optimized posts, PDFs, reviews and counterfeit support pages containing fraudulent phone numbers, email addresses and login links.
Named targets include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb and TripAdvisor. The deceptive material has appeared across social networks, file-upload services, Google Sites, GitHub Pages, WordPress, Blogger, Yelp and Apple Maps. Fundraising, employment and event platforms—including Posh.vip, onecause.com, bebee.com and raiselysite.com—have also been used.
Users should not treat an AI-generated support number as verified. Contact details should be checked against the company’s official website or application before sharing credentials, account information or payment data.
MAX gives its host app control over mini-app security
Researchers from the University of Michigan, University of Calgary, Georgia Institute of Technology and Indian Institute of Technology Delhi examined MAX, a Russian state-backed super-app developed by VK.
MAX combines messaging with banking, e-commerce and government services. The forensic study found that its architecture gives the host application extensive control over mini-apps running inside it.
The researchers documented five capabilities. MAX can capture mini-app screens without special system permissions or user notification; read and modify mini-app local storage; inject JavaScript at runtime; mediate network traffic; and control authentication tokens and session context.
In the Russian regional build, mini-app traffic passes through a GOST TLS proxy. This design raises the possibility of state-level interception because the host platform sits between a mini-app and its network destination.
Control over tokens also means MAX can potentially impersonate a user to services operating inside its ecosystem. Security properties presented by an individual mini-app may therefore be weakened by the broader platform in which it runs.
Industrial operators are told to constrain integrator access
The FBI and CISA have published guidance for critical-infrastructure operators using third-party ICS integrators. The fact sheet’s initial version is dated September 23, 2026.
Integrators may install and support supervisory control and data acquisition systems, programmable logic controllers and other operational technology. They can also receive persistent remote access, detailed equipment information and influence over physical processes.
The agencies linked those risks to a compromise between March and April 2025. Foreign malicious actors entered the network of a U.S. industrial-automation company serving customers that included power and transportation organizations.
The intruders searched for terms including “customers” and “SCADA,” then created nine ZIP archives containing roughly 800 files for presumed exfiltration. The material included customer SCADA information, ICS device details and schematics that could assist later attacks on operational environments.
CISA recommends applying least privilege to integrator accounts, logging remote sessions and preferring access that operators must explicitly approve. Organizations should also identify internet-exposed devices, inventory integrator-supplied hardware and software, document update mechanisms and specify cybersecurity obligations in contracts.
Recovery plans should assume the integrator becomes unavailable or compromised. That includes rehearsing manual operations and retaining secure offline copies of software needed to operate equipment.
Compromised WordPress updates and an exploited WinRAR flaw
A malicious Admin Menu Editor Pro update was uploaded to adminmenueditor[.]com on September 14, 2026. Customers received it as version 2.35.
The altered package added includes/wp-user-consent.php, which installed a web shell on WordPress sites. Maintainer Janis Elsts released a clean version 2.36 that day, but attackers compromised it again. That recurrence suggested they might have obtained root-level access to the update server.
The earliest identified compromise activity occurred on September 13, 2026, at approximately 7:40 p.m. UTC. Elsts attributed the initial server breach to a vulnerability in an outdated Linux kernel.
At least 230 customers installed the malicious update across 1,500 websites. As of September 20, version 2.37 was available to customers who lacked a clean plugin copy, while the licensing API and update infrastructure were being substantially rebuilt.
Administrators should look for the unexpected includes/wp-user-consent.php file, replace the plugin with a verified clean release and investigate affected servers for activity enabled by the web shell. Merely updating the plugin may not remove changes made after the shell was installed.
Separately, CVE-2023-38831 affects RARLAB WinRAR versions earlier than 6.23. A crafted ZIP archive can contain an apparently harmless file, such as a .JPG, and a folder with the same name. Opening the decoy causes WinRAR to process executable content placed inside the corresponding folder.
The flaw requires user interaction but no existing attacker privileges. It carries a CVSS 3.1 score of 7.8, with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Exploitation was recorded from April through October 2023, including use in ransomware campaigns. CISA added it to the Known Exploited Vulnerabilities catalog on August 24, 2023, setting a September 14, 2023 remediation deadline for U.S. federal agencies. CISA requires affected organizations to apply vendor mitigations or stop using the product if mitigations are unavailable. Upgrading to WinRAR 6.23 or later removes the affected pre-6.23 versions.
Social engineering and endpoint evasion keep evolving
A fake Claude Max promotion demonstrates how carefully designed interfaces can defeat visual checks. The page promised a free upgrade and presented a fraudulent Google login window drawn inside the existing browser tab.
This browser-in-the-browser window displayed a padlock and a correctly spelled Google sign-in address. It could also be dragged, making it resemble a separate browser window. Users should verify that authentication occurs in a genuine browser window and confirm the actual address shown by the browser itself.
Meanwhile, researchers Max Hirschberger and Ogulcan Ugur detailed Process Parameter Poisoning in July 2026. Flashpoint later released a Rust proof of concept combining parameter spoofing with thread-execution hijacking.
Rather than allocating target-process memory and writing a payload through commonly monitored APIs, the method places malicious code in normal process-initialization structures during creation. Flashpoint says this can evade EDR products that depend heavily on API hooking during early execution.
Other developments include Exvicy, a ClickFix malware-as-a-service framework that uses compromised WordPress sites and fake Cloudflare CAPTCHA checks to direct users to the Windows Run dialog. Advertised on Exploit.in from May 26, 2026, it initially cost $1,200 per month and increased to $2,000 in mid-August.
Canonical is also moving Ubuntu kernel CVE fixes to overlapping two-week cycles, producing weekly kernel releases. The company attributed the change to a sharp increase in CVE volume, driven mainly by AI.
Finally, the FBI reported nearly 61,000 complaints about government and law-enforcement impersonation scams between January 2025 and July 2026. Reported losses exceeded $1.6 billion. Common warning signs include demands for secrecy, sustained phone pressure and aggressive claims that only the targeted person may discuss the supposed case.
Sources
This article is an original reworking based on the sources below.
- primary sourceCISA
- primary sourceNVD (NIST)
- The Hacker News




