Copybara Android RAT Spreads via Fake N26 Support Calls to Control Banking Apps
Key Takeaways A sophisticated fraud campaign is targeting Android users of N26 banking through vishing and malware. The attack chain involves social engineering, fake login pages, and the deployment...
Key Takeaways
- A sophisticated fraud campaign is targeting Android users of N26 banking through vishing and malware.
- The attack chain involves social engineering, fake login pages, and the deployment of the Copybara Android Remote Access Trojan (RAT).
- Copybara exploits Android’s Accessibility Services to gain extensive control over victim devices, including banking apps.
- Attackers can remotely control compromised phones, execute transactions, and exfiltrate sensitive data while displaying a fake loading screen.
- Users should be highly suspicious of unsolicited calls claiming to be from their bank and avoid installing applications from unofficial sources.
A new and dangerous fraud operation is actively targeting Android users of the N26 banking platform. This campaign initiates with convincing voice phishing (vishing) calls that impersonate N26 support personnel, ultimately leading to criminals gaining complete remote control over victims’ banking applications and devices.
Table Of Content
The attackers employ a multi-stage approach. They first trick individuals into believing their accounts require urgent verification or a device certification update. This manipulation guides victims to a fraudulent login page, where their credentials are stolen. Subsequently, victims are persuaded to install a malicious Android application from an unofficial source.
Security researchers at d3 Lab said in a report that this elaborate scheme orchestrates social engineering, a real-time phishing panel, and malware delivery into a cohesive and highly effective operation. The malware, identified as Copybara, is an Android Remote Access Trojan (RAT) specifically designed to steal data and execute unauthorized actions by abusing legitimate Android accessibility permissions.
The severity of this campaign surpasses typical fake banking page scams. Once Copybara is installed, attackers can display a deceptive N26 loading screen to the victim while simultaneously operating the phone in the background. This covert access allows them to potentially interact with financial applications, read private messages, and initiate fraudulent transactions without the victim’s immediate awareness.
Fake N26 Support Calls Deploy Copybara Android RAT
The attack sequence typically commences with a series of phone calls, either from an automated system or a live individual posing as N26 customer support. The caller creates a false sense of urgency regarding the security of the victim’s account, then redirects them away from official banking channels to attacker-controlled contact points. This tactic aligns with prevalent voice phishing methodologies, which exploit trust rather than relying solely on software vulnerabilities.
After a victim provides their credentials on a spoofed N26 website, the attackers prompt them to download and install an Android application package (APK), falsely presented as a critical “certification component.” This initial application is named “N26 Pdf” with the package identifier io.smart.evolve and displays an update screen labeled “Certificato N26.”
The malicious application requests permission to install apps from unknown sources, a crucial step for deploying its hidden second-stage payload. During this process, it also momentarily establishes a local VPN rule that impacts the Google Play Store. Researchers speculate this action is intended to bypass or interfere with Google’s security checks while the malware installation is underway.
The embedded Copybara payload, masquerading as “Certificato N26,” later presents a generic “Battery Cleaner Pro” interface. This interface is purely cosmetic; its displayed battery, memory, temperature, and cleaning statistics are hard-coded and do not reflect actual device utility. This deceptive use of a seemingly benign application is a common strategy in fake banking app campaigns, where attackers depend on victims granting invasive permissions after installing an unofficial APK.
Remote Access Behind the Screen
Copybara leverages Android’s Accessibility Services, a legitimate feature designed to assist users with disabilities, for malicious purposes. Once activated, the RAT gains the ability to perform a wide range of actions, including simulating taps, swipes, text input, executing global system actions, and capturing information displayed within active application windows.
Beyond screen manipulation, the malware is capable of exfiltrating sensitive data such as SMS messages, contact lists, call logs, installed applications, and unique device identifiers. Its extensive functionalities include keylogging, screen streaming, screen capture, microphone recording, camera access, file downloads, installation of additional APKs, suppression of notifications, and attempts to prevent its own removal.
Attackers maintain communication with compromised devices through MQTT services hosted on a pre-configured server. The campaign utilizes two distinct MQTT channels: one for transmitting commands and another for bandwidth-intensive activities like camera access and screen capture, providing operators with a direct and comprehensive means to remotely control the infected device.
The white N26-branded overlay screen observed by victims is particularly concerning. It effectively masks malicious activity occurring in the background. Instead of directly circumventing biometric security, attackers can exploit this visual deception, leading victims to unknowingly approve legitimate prompts for fraudulent transactions without fully understanding what they are authorizing.
What You Should Do
- Always treat unsolicited calls claiming to be from your bank with extreme skepticism. Hang up and contact your bank directly using the official phone number found on their website or banking app.
- Never install applications from unknown sources or through links sent via text messages or emails, especially if prompted by an unexpected call.
- Be highly cautious of any application requesting extensive Accessibility Service permissions, as these are frequently abused by malware.
- Regularly review the permissions granted to applications on your Android device and revoke any that seem unnecessary or suspicious.
- Keep your Android operating system and all applications updated to ensure you have the latest security patches.
- Utilize a reputable mobile security solution on your Android device to detect and prevent malware infections.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a |
Malicious outer dropper |
| SHA-256 | 0475a46c70d8671322d39392c55d404b6d8f4de34090f0373244cef52ae55708 |
Decrypted JAR loader |
| SHA-256 | b88668403a6dabe4867573fc23c11ce937291f6aab7e65e8261b4c967ab2e68c |
Loader DEX |
| SHA-256 | 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412 |
Copybara embedded payload APK |
| MD5 | e792fedfd11d56a9ad68e6d407b9a09e |
Copybara embedded payload APK |
| Package | io.smart.evolve |
N26 Pdf dropper package |
| Package | com.upy2dl.ptroa5 |
Copybara payload package |
| Domain | n26portale[.]com |
Phishing and Fake Control infrastructure |
| Domain | n26[.]com[.]de |
Fraudulent support email infrastructure |
assistenza@n26[.]com[.]de |
Campaign contact address | |
| IPv4 | 37[.]148[.]161[.]44 |
Copybara command-and-control and content host |
| Port | 52997/TCP |
Primary MQTT command channel |
| Port | 52998/TCP |
Camera and MediaProjection MQTT channel |
| MQTT Topic | commandsFromPC |
Copybara command channel |
| Filename | WJcugJ.jar |
Encrypted loader marker |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.