Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitLab Patches Critical Flaws Letting Attackers Leak Data, Alter Pipelines
July 30, 2026
Linux Cryptomining Campaign Leverages PAM to Conceal XMRig Botnet
July 30, 2026
Critical Microsoft Teams Vulnerability Lets Attackers Install Ransomware
July 30, 2026
Home/CyberSecurity News/Copybara Android RAT Spreads via Fake N26 Support Calls to Control Banking Apps
CyberSecurity News

Copybara Android RAT Spreads via Fake N26 Support Calls to Control Banking Apps

Key Takeaways A sophisticated fraud campaign is targeting Android users of N26 banking through vishing and malware. The attack chain involves social engineering, fake login pages, and the deployment...

David kimber
David kimber
July 30, 2026 4 Min Read
4 0

Key Takeaways

  • A sophisticated fraud campaign is targeting Android users of N26 banking through vishing and malware.
  • The attack chain involves social engineering, fake login pages, and the deployment of the Copybara Android Remote Access Trojan (RAT).
  • Copybara exploits Android’s Accessibility Services to gain extensive control over victim devices, including banking apps.
  • Attackers can remotely control compromised phones, execute transactions, and exfiltrate sensitive data while displaying a fake loading screen.
  • Users should be highly suspicious of unsolicited calls claiming to be from their bank and avoid installing applications from unofficial sources.

A new and dangerous fraud operation is actively targeting Android users of the N26 banking platform. This campaign initiates with convincing voice phishing (vishing) calls that impersonate N26 support personnel, ultimately leading to criminals gaining complete remote control over victims’ banking applications and devices.

Table Of Content

  • Key Takeaways
  • Fake N26 Support Calls Deploy Copybara Android RAT
  • Remote Access Behind the Screen
  • What You Should Do

The attackers employ a multi-stage approach. They first trick individuals into believing their accounts require urgent verification or a device certification update. This manipulation guides victims to a fraudulent login page, where their credentials are stolen. Subsequently, victims are persuaded to install a malicious Android application from an unofficial source.

Security researchers at d3 Lab said in a report that this elaborate scheme orchestrates social engineering, a real-time phishing panel, and malware delivery into a cohesive and highly effective operation. The malware, identified as Copybara, is an Android Remote Access Trojan (RAT) specifically designed to steal data and execute unauthorized actions by abusing legitimate Android accessibility permissions.

The severity of this campaign surpasses typical fake banking page scams. Once Copybara is installed, attackers can display a deceptive N26 loading screen to the victim while simultaneously operating the phone in the background. This covert access allows them to potentially interact with financial applications, read private messages, and initiate fraudulent transactions without the victim’s immediate awareness.

Fake N26 Support Calls Deploy Copybara Android RAT

The attack sequence typically commences with a series of phone calls, either from an automated system or a live individual posing as N26 customer support. The caller creates a false sense of urgency regarding the security of the victim’s account, then redirects them away from official banking channels to attacker-controlled contact points. This tactic aligns with prevalent voice phishing methodologies, which exploit trust rather than relying solely on software vulnerabilities.

After a victim provides their credentials on a spoofed N26 website, the attackers prompt them to download and install an Android application package (APK), falsely presented as a critical “certification component.” This initial application is named “N26 Pdf” with the package identifier io.smart.evolve and displays an update screen labeled “Certificato N26.”

The malicious application requests permission to install apps from unknown sources, a crucial step for deploying its hidden second-stage payload. During this process, it also momentarily establishes a local VPN rule that impacts the Google Play Store. Researchers speculate this action is intended to bypass or interfere with Google’s security checks while the malware installation is underway.

The embedded Copybara payload, masquerading as “Certificato N26,” later presents a generic “Battery Cleaner Pro” interface. This interface is purely cosmetic; its displayed battery, memory, temperature, and cleaning statistics are hard-coded and do not reflect actual device utility. This deceptive use of a seemingly benign application is a common strategy in fake banking app campaigns, where attackers depend on victims granting invasive permissions after installing an unofficial APK.

Remote Access Behind the Screen

Copybara leverages Android’s Accessibility Services, a legitimate feature designed to assist users with disabilities, for malicious purposes. Once activated, the RAT gains the ability to perform a wide range of actions, including simulating taps, swipes, text input, executing global system actions, and capturing information displayed within active application windows.

Beyond screen manipulation, the malware is capable of exfiltrating sensitive data such as SMS messages, contact lists, call logs, installed applications, and unique device identifiers. Its extensive functionalities include keylogging, screen streaming, screen capture, microphone recording, camera access, file downloads, installation of additional APKs, suppression of notifications, and attempts to prevent its own removal.

Attackers maintain communication with compromised devices through MQTT services hosted on a pre-configured server. The campaign utilizes two distinct MQTT channels: one for transmitting commands and another for bandwidth-intensive activities like camera access and screen capture, providing operators with a direct and comprehensive means to remotely control the infected device.

The white N26-branded overlay screen observed by victims is particularly concerning. It effectively masks malicious activity occurring in the background. Instead of directly circumventing biometric security, attackers can exploit this visual deception, leading victims to unknowingly approve legitimate prompts for fraudulent transactions without fully understanding what they are authorizing.

What You Should Do

  • Always treat unsolicited calls claiming to be from your bank with extreme skepticism. Hang up and contact your bank directly using the official phone number found on their website or banking app.
  • Never install applications from unknown sources or through links sent via text messages or emails, especially if prompted by an unexpected call.
  • Be highly cautious of any application requesting extensive Accessibility Service permissions, as these are frequently abused by malware.
  • Regularly review the permissions granted to applications on your Android device and revoke any that seem unnecessary or suspicious.
  • Keep your Android operating system and all applications updated to ensure you have the latest security patches.
  • Utilize a reputable mobile security solution on your Android device to detect and prevent malware infections.

Indicators of Compromise (IoCs):

Type Indicator Description
SHA-256 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a Malicious outer dropper
SHA-256 0475a46c70d8671322d39392c55d404b6d8f4de34090f0373244cef52ae55708 Decrypted JAR loader
SHA-256 b88668403a6dabe4867573fc23c11ce937291f6aab7e65e8261b4c967ab2e68c Loader DEX
SHA-256 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412 Copybara embedded payload APK
MD5 e792fedfd11d56a9ad68e6d407b9a09e Copybara embedded payload APK
Package io.smart.evolve N26 Pdf dropper package
Package com.upy2dl.ptroa5 Copybara payload package
Domain n26portale[.]com Phishing and Fake Control infrastructure
Domain n26[.]com[.]de Fraudulent support email infrastructure
Email assistenza@n26[.]com[.]de Campaign contact address
IPv4 37[.]148[.]161[.]44 Copybara command-and-control and content host
Port 52997/TCP Primary MQTT command channel
Port 52998/TCP Camera and MediaProjection MQTT channel
MQTT Topic commandsFromPC Copybara command channel
Filename WJcugJ.jar Encrypted loader marker

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Anthropic Claude Opus 5 AI Deletes Production Database

Next Post

Cybercrime Platform Leverages Helpdesk Calls for Enterprise Account Takeovers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Cybercrime Platform Leverages Helpdesk Calls for Enterprise Account Takeovers
July 30, 2026
Copybara Android RAT Spreads via Fake N26 Support Calls to Control Banking Apps
July 30, 2026
Anthropic Claude Opus 5 AI Deletes Production Database
July 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us