At a glance
| Malware family | Copybara (Android RAT) |
| Operators | Not attributed; kit uses Portuguese-language identifiers |
| Targets | N26 banking customers in Italy |
| Delivery vector | Vishing call, phishing login page, sideloaded APK |
| Key capabilities | Accessibility remote control, keylogging, screen capture, SMS theft, overlays |
| Source | D3Lab |
TL;DR
Researchers at D3Lab tracked a live fraud campaign that impersonates the bank N26 in Italy. It starts with a fake support call and ends with a Copybara Android RAT running on the victim’s phone. A real-time phishing panel and a multistage dropper connect those two stages.
How the scam starts
The campaign first surfaced when ShadowOpCode flagged it on X, pointing to a detailed victim account on Reddit.
The attack opens with a phone call, not a link. An automated message warns that the account needs extra verification. Then a fake N26 “representative” walks the victim through a bogus device “certification” process.
The operator quotes real messages from inside the banking app to sound convincing. Next, the victim moves off the bank’s trusted channel to a fraudulent support address. That reply points to an N26-themed login page on an attacker domain.
A phishing panel run by a human
The login page is not static. D3Lab links it to a web panel called Fake Control 1.0, built on the AdminLTE dashboard template. As the report puts it, “This is not simply a credential-harvesting website.”
Instead, the operator watches each victim in real time. The panel collects credentials and one-time codes, refreshes every few seconds, and controls what the victim sees next. It also serves the malicious APK. D3Lab calls it “an interactive social-engineering console rather than a static login clone.”
The Copybara Android RAT payload
The downloaded app poses as a component named Certificato N26. Behind that cover sits a multistage dropper that hides an encrypted payload. After several unpacking steps, it installs the Copybara Android RAT.
The installed app then shows a fake utility called Battery Cleaner Pro. Its stats are hard-coded in local HTML. As D3Lab notes, “Battery Cleaner Pro therefore provides cover, not device maintenance.”
D3Lab attributes the payload to Copybara with high confidence. That call rests on its B4A/B4X codebase, MQTT channels, and command vocabulary. Copybara is a known family that ThreatFabric first documented in vishing-led attacks on Italian banks.
Command, control, and theft
Copybara abuses Android’s Accessibility service as a remote-control channel. It can drive taps, swipes, and text entry across the real banking apps. Meanwhile, an N26-branded white screen hides that activity from the victim.
The command set is large. The RAT can log keystrokes, stream the screen, record audio, and capture the camera. It can also read, send, and delete SMS, then exfiltrate contacts and device data.
For control, the payload contacts a hardcoded IP address over MQTT. It uses one channel for commands and a separate one for camera and screen traffic. Overlay targets arrive from the server, so operators can switch brands without rebuilding the app.
Confirmed targets
N26 is the confirmed lure. In one victim case, the report also observed activity around Poste, Intesa Sanpaolo, and Microsoft Authenticator. Treat those as observed apps, not a full target list.
How to defend against it
Banks never ask you to install a “certification” app during a call. So treat any such request as fraud and hang up. Only install apps from official stores, and refuse sideloaded APKs.
Watch for apps that demand Accessibility, device-admin, or install permissions. A sudden full-screen “loading” cover during banking is a warning sign. For the full technical breakdown and indicators, read the D3Lab report.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.