VYPR
researchPublished Jul 30, 2026· 1 source

Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps

A new Android malware campaign impersonates N26 support to trick users into installing the Copybara RAT, enabling remote control of banking apps.

A sophisticated fraud campaign is targeting Android banking users by impersonating N26 support staff through convincing phone calls. The attack, identified by researchers at d3 Lab, begins with voice phishing and can escalate to criminals remotely controlling victims' banking applications.

Attackers initiate the campaign by contacting potential victims with automated messages or live calls claiming to be from N26 support. They create a sense of urgency regarding account security, then steer users away from official channels towards attacker-controlled contact information. This social engineering tactic leverages trust to bypass typical security measures, a common pattern in voice phishing operations.

Following the initial contact, victims are guided to a fake N26-themed login page where their credentials are harvested. Subsequently, the attackers persuade the victims to install a malicious Android application, disguised as a necessary update, from outside official app stores. This multi-stage approach combines social engineering, a live phishing panel, and malware delivery into a coordinated operation.

The malicious application, named "N26 Pdf" with the package name io.smart.evolve, requests users to enable installations from unknown sources. Researchers believe the campaign may also temporarily disrupt Google Play Store security checks by creating a local VPN rule, facilitating the malware installation. The app then installs a hidden second-stage payload, the Copybara RAT.

The embedded Copybara payload, presented under the guise of "Certificato N26" or a generic "Battery Cleaner Pro" interface, abuses Android's Accessibility permissions. This legitimate feature, designed for user assistance, is weaponized by the malware to perform actions like taps, swipes, text entry, and to capture information from active app windows, including sensitive banking data.

With Accessibility permissions granted, Copybara can log keystrokes, stream the screen, capture screenshots, record audio, access the camera, download files, install additional applications, suppress notifications, and interfere with malware removal attempts. Attackers communicate with infected devices via MQTT services hosted on a hard-coded server, using separate channels for commands and higher-volume data exfiltration like screen captures.

The campaign's ability to display a seemingly legitimate N26-branded screen while operating in the background is particularly concerning. This can mask malicious activities, potentially allowing attackers to bypass biometric protections by tricking users into approving real prompts without realizing the underlying actions being authorized.

Users are strongly advised to treat unsolicited banking support calls with extreme suspicion, ending the call and contacting their bank only through official channels. Installing APKs from unknown sources or accepting unusual accessibility permission requests should be avoided to mitigate the risk of falling victim to such sophisticated attacks.

Synthesized by Vypr AI