Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android dropper to gain full remote control of victims’ phones via abused Accessibility services.
The operator leverages real notifications already present in the legitimate N26 app to build trust, then pushes the victim away from official channels toward a rogue support email.
That address returns an N26‑branded login page hosted on attacker infrastructure, where credentials and one‑time codes are harvested before the victim is instructed to download an “N26 Pdf” Android package and grant Accessibility, device control, location, and other invasive permissions.
Once granted, a full‑screen white N26 loading screen hides the real activity. At the same time, the attacker begins manipulating financial applications beneath it.
The web component behind the phishing site matches a kit known as Fake Control 1.0, built with PHP, SQLite, JavaScript, and an AdminLTE‑based dashboard.
Rather than a static credential‑harvesting page, it operates as an interactive console: victim sessions are tracked in SQLite databases, operator dashboards update every few seconds, and commands can change what the victim sees in real time, invalidate tokens, lure victims with “transaction cancelled” messages, or trigger APK delivery.
Portuguese identifiers such as senha, acesso, gerente and enviarComando point to the language ecosystem but not necessarily the operators’ location.
URL parameters separate verification, session, and attempt tracking, allowing a phone operator to follow a single victim’s journey and coordinate page content with the phone conversation.
The Android delivery stage uses a dropper branded as N26 Pdf with package io.smart.evolve. It copies an embedded APK, requests installation from unknown sources and uses a foreground observer to poll the permission state every 800 ms, resuming as soon as installation is allowed.
The dropper creates a local per‑app VPN for com.android.vending, routing Play Store traffic into a local TUN interface and discarding packets for roughly 240 seconds, likely to disrupt Play Protect checks during installation.
Both the outer APK and embedded payload are loaded with structural anomalies: conflicting ZIP compression metadata, extreme‑length asset paths, random Unicode components.
Resource collisions that make conventional tooling fail, forcing analysts to reconstruct the chain manually from an encrypted JAR, RC4 decryption, a dynamic loader DEX, and an embedded base.apk that ultimately delivers the Copybara RAT.
D3 Lab Researchers said that, the operation starts with voice phishing: victims receive automated and live calls from actors impersonating N26 support, claiming additional verification is required.
The embedded payload, labeled Certificato N26 (com.upy2dl.ptroa5), is attributed to Copybara based on its B4A/B4X codebase, MQTT command channels on TCP ports 52997 and 52998, commands_FromPC topics, and serialized command maps.
It declares dozens of activities, services and receivers, including an Accessibility service, notification listener, device‑admin receiver, SMS handlers, microphone and MediaProjection components, plus boot persistence.
Copybara turns Accessibility from an assistive technology into a remote‑control surface: it can drive clicks and swipes, enter text, capture the UI hierarchy, implement keylogging, stream the screen, record microphone and camera, and abuse its device‑admin privileges to resist removal.
A secondary MQTT channel carries higher‑volume screen and camera data, while HTTP services on the same 37[.]148[.]161[.]44 host supply overlays, lock‑screen content and imagery.
To avoid suspicion once the N26 branding has served its purpose, Copybara presents itself as Battery Cleaner Pro, a multilingual decoy interface implemented with localized HTML pages and static “optimization” values.
The N26 operation documented here fits that evolution: a human‑operated workflow that fuses social engineering, real‑time web control, and an Android RAT capable of full device takeover through Accessibility.
The page is loaded in a WebView, checks whether the malicious Accessibility service is enabled, and prods the user to activate it under plausible battery‑health pretexts.
This decoy legitimizes intensive background activity and persistent permissions while the RAT streams the screen and drives banking apps invisibly under an N26 cover layer.
On the server side, Copybara receives overlay instructions as inj structures mapping application packages to template names; N26 is confirmed as the current lure, with Poste, Intesa Sanpaolo and Microsoft Authenticator mentioned in victim reporting as observed targets.
Copybara has been active since at least 2021 in Italian TOAD‑style vishing campaigns and is frequently confused with BRATA due to shared banking‑trojan tradecraft and MQTT‑based command channels.
For defenders, traditional URL and credential‑phishing detection is no longer sufficient; visibility into Accessibility misuse, anomalous VPN creation targeting Play Store traffic, and MQTT‑driven remote‑control behavior is now critical for detecting Copybara and similar Android banking RATs before on‑device fraud unfolds.
| Type | Indicator | Role |
|---|---|---|
| SHA-256 | 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a | Malicious dropper |
| SHA-256 | 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412 | Copybara payload |
| Package | io.smart.evolve | Dropper package |
| Package | com.upy2dl.ptroa5 | Payload package |
| Domain | n26portale[.]com | Phishing and Fake Control infrastructure |
| Domain | n26[.]com[.]de | Fraudulent support-mail infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…