Skip to content
Malware

Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps

A new fraud campaign is targeting Android banking users through convincing phone calls that impersonate N26 support staff. The attack begins as voice phishing, but it can end with criminals remotely controlling banking apps on a victim’s phone. Victims are told that their account needs urgent verifi...

· Jul 30, 2026 · 4 min read · 👁 3 views
Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps

A new fraud campaign is targeting Android banking users through convincing phone calls that impersonate N26 support staff. The attack begins as voice phishing, but it can end with criminals remotely controlling banking apps on a victim’s phone.

Victims are told that their account needs urgent verification or a device certification update.

Attackers then guide them to a fake login page, collect credentials, and persuade them to install a malicious Android application outside the official app store.

Researchers at d3 Lab identified the malware as Copybara, an Android remote access trojan built to steal data and perform actions through abused accessibility permissions.

d3 Lab said in a report shared with Cyber Security News (CSN) that the campaign combines social engineering, a live phishing panel, and malware delivery into one coordinated operation.

The result is more dangerous than a typical fake banking page. Attackers can keep victims occupied with a false N26 loading screen while using the phone in the background, potentially accessing financial apps, reading messages, and attempting transactions.

Fake N26 Support Calls Deploy Copybara Android RAT

The campaign reportedly starts with repeated calls from an automated message or a person claiming to represent N26 support.

The caller creates urgency around account security, then moves the target away from trusted banking channels and toward attacker-controlled contact details. This mirrors broader voice phishing attack patterns that rely on trust instead of software exploits.

A phishing site (Source - d3 Lab)
A phishing site (Source – d3 Lab)

After the victim enters credentials on an N26-themed site, the attackers offer an Android package presented as a certification component.

The outer application calls itself “N26 Pdf” and uses the package name io.smart.evolve, while displaying an update screen for “Certificato N26.”

The app asks the victim to allow installations from unknown sources, then installs a hidden second-stage payload.

It also temporarily creates a local VPN rule affecting the Google Play Store, an action researchers believe may disrupt security checks while the malware installation is underway.

The embedded Copybara payload is disguised as “Certificato N26” and later presents a generic Battery Cleaner Pro interface. That screen is merely cover: its battery, memory, temperature, and cleaning information is hard-coded rather than generated by a real utility.

This use of a familiar-looking app follows the same strategy seen in fake banking app campaigns, where attackers depend on a victim installing an APK and approving invasive permissions.

Remote Access Behind the Screen

Copybara abuses Android Accessibility, a legitimate feature intended to help users interact with their devices. Once enabled, it can perform taps, swipes, text entry, global actions, and capture information visible in active app windows.

The malware can also collect SMS messages, contacts, call logs, installed-app lists, device identifiers, and other phone information.

Fake Control 1.0 (Source - d3 Lab)
Fake Control 1.0 (Source – d3 Lab)

Its available functions include keylogging, screen streaming, screen capture, microphone recording, camera access, file downloads, additional APK installation, notification suppression, and attempts to interfere with removal.

Attackers communicate with infected phones through MQTT services hosted on a hard-coded server.

The campaign uses one channel for commands and another for higher-volume activities such as camera access and screen capture, giving operators a direct route to manipulate the device remotely.

The white N26-branded screen reported by a victim is especially concerning because it can hide activity happening underneath. Rather than breaking biometric protections, attackers may rely on victims to approve a real prompt without seeing what is actually being authorized.

Certificato N26 (Source - d3 Lab)
Certificato N26 (Source – d3 Lab)

Users should treat unsolicited banking support calls as suspicious, end the call, and contact their bank only through its official application or published number.

They should never install an APK sent by a caller, text message, or email, and should be wary of unexpected accessibility requests, as explained in coverage of accessibility permission abuse risks.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-256464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4aMalicious outer dropper
SHA-2560475a46c70d8671322d39392c55d404b6d8f4de34090f0373244cef52ae55708Decrypted JAR loader
SHA-256b88668403a6dabe4867573fc23c11ce937291f6aab7e65e8261b4c967ab2e68cLoader DEX
SHA-2567cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412Copybara embedded payload APK
MD5e792fedfd11d56a9ad68e6d407b9a09eCopybara embedded payload APK
Packageio.smart.evolveN26 Pdf dropper package
Packagecom.upy2dl.ptroa5Copybara payload package
Domainn26portale[.]comPhishing and Fake Control infrastructure
Domainn26[.]com[.]deFraudulent support email infrastructure
Emailassistenza@n26[.]com[.]deCampaign contact address
IPv437[.]148[.]161[.]44Copybara command-and-control and content host
Port52997/TCPPrimary MQTT command channel
Port52998/TCPCamera and MediaProjection MQTT channel
MQTT TopiccommandsFromPCCopybara command channel
FilenameWJcugJ.jarEncrypted loader marker

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you