Threat reportMalwareTL-2026-1804
Copybara Android RAT Delivered via Fake N26 Support Vishing Calls
Copybara Android RAT Delivered via Fake N26 Support Vishing (TL-2026-1804), also tracked as Certificato N26 Campaign, is a high-severity malware campaign, first published 2026-08-01. It has no confirmed attribution, affects Google Android OS, maps to 39 MITRE ATT&CK techniques (T1204.002, T1398, T1406.002), and is covered by 9 detection rules and 55 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 39MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 55Indicators of compromise
Key facts for TL-2026-1804
- Threat ID
- TL-2026-1804
- Also known as
- Certificato N26 Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, digital banking, consumer banking
- Target regions
- italy, spain, Europe
- Detection rules
- 9
- Indicators of compromise
- 55
- Updates
- 2026-08-01 · revalidated 1× · latest source
Malware and tooling in Copybara Android RAT Delivered via Fake N26 Support Vishing
Malware and tooling: BRATA, BRATA - S1094, N26 Pdf, B4A (Basic4Android), MQTT
How Copybara Android RAT Delivered via Fake N26 Support Vishing works
A fraud campaign impersonates N26 bank support via vishing calls to steer victims through a live phishing panel and a trojanized 'certification update' APK that installs the Copybara Android RAT. Copybara abuses Accessibility Services for full remote device control -- keylogging, screen/microphone/camera capture, SMS and contact theft, and additional APK installation -- enabling banking-app account takeover.
Researchers at d3 Lab, in analysis shared with Cyber Security News and published 2026-07-30, documented a coordinated fraud operation targeting customers of the German neobank N26. The campaign chains voice phishing (vishing), a real-time phishing control panel, and a multi-stage Android dropper to achieve full remote control of victim devices via abused Accessibility Services.
The attack begins with a credential-harvesting phishing page (n26portale[.]com) that collects account number, PIN, telephone number, and security-question answers -- consistent with the Telephone-Oriented Attack Delivery (TOAD) tradecraft d3Lab/Tinexta Cyber previously documented against Italian banks. Victims are then called by an operator or automated message impersonating N26 support (using fraudulent contact infrastructure at n26[.]com[.]de, email assistenza@n26.com.de), who creates urgency around 'account security' and a required 'certification update,' and walks the victim through sideloading an APK outside the Play Store.
The outer dropper, packaged as io.smart.evolve and labeled 'N26 Pdf' (also referenced internally as 'Certificato N26'), decrypts and loads an embedded JAR (marker filename WJcugJ.jar) which in turn installs the Copybara payload (com.upy2dl.ptroa5). The dropper/payload combination uses structural anomalies -- conflicting ZIP compression metadata, extreme-length asset paths, random Unicode path components, and resource collisions -- to defeat conventional static-analysis tooling. During installation the victim is repeatedly prompted (notification harassment) to enable Accessibility Service and Device Administrator permissions; once granted, Copybara transforms the Accessibility API into a full remote-control surface: simulated taps/swipes/text entry, UI-hierarchy extraction, keylogging, real-time screen streaming, camera (front/rear) and microphone capture via MediaProjection, SMS/contact/call-log theft, installed-app enumeration, and silent installation of additional APKs. The malware also temporarily installs local VPN rules that researchers believe interfere with Google Play Protect scanning during install, and abuses Accessibility-granted control of the Settings app to block victims from reaching the uninstall screen.
Command and control runs over MQTT to 37[.]148[.]161[.]44: TCP 52997 carries the primary command channel (topic commandsFromPC / commands_FromPC, exfiltrating to sub-topics such as med, divap_topc, and Device_Calls_Logs_Save), while TCP 52998 carries higher-volume camera and MediaProjection screen data; an HTTP service on the same IP delivers overlay HTML and lock-screen content. During active fraud, operators display a false N26 'loading screen' overlay via WebView to occupy the victim while using Accessibility-driven input injection in the background to open financial apps, read incoming SMS one-time passcodes, and attempt fraudulent transactions.
Copybara is not a novel family: it has been active since at least November 2021 in Italian TOAD-style vishing campaigns targeting banking and (per Zscaler ThreatLabz) cryptocurrency-exchange credentials, is built on the B4A/B4X (Basic4Android) legitimate app-development framework, and shares banking-trojan tradecraft and MQTT-based C2 architecture with the BRATA malware lineage without being a direct BRATA derivative. This N26-themed wave, first surfaced 2026-07-30, is the newest observed target-brand rotation of an established, actively maintained TOAD delivery chain. No CVE applies -- the campaign relies entirely on social engineering and Android Accessibility Service abuse, not a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1804
Execution
Persistence
T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence
defense-evasion
T1406.002 Software Packing; T1407 Download New Code at Runtime; T1628.001 Suppress Application Icon; T1628.002 User Evasion; T1629.001 Prevent Application Removal; T1630.003 Disguise Root/Jailbreak Indicators; T1633.001 System Checks
Collection
T1414 Clipboard Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1533 Data from Local System; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages
collection
credential-access
Discovery
T1418 Software Discovery; T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery
command-and-control
T1437 Application Layer Protocol; T1509 Non-Standard Port
initial-access
T1444 Masquerade as Legitimate Application; T1476 Deliver Malicious App via Other Means; T1660 Phishing
Impact
T1516 Input Injection; T1582 SMS Control
Resource Development
T1583.001 Domains; T1583.004 Server; T1587.001 Malware
Reconnaissance
T1598 Phishing for Information; T1598.004 Spearphishing Voice
persistence
privilege-escalation
T1626.001 Device Administrator Permissions
Exfiltration
Affected products and versions in Copybara Android RAT Delivered via Fake N26 Support Vishing
- Google — Android OS
Vulnerable versions: Any Android version where sideloading (install from unknown sources) is permitted and Accessibility Service can be granted to a sideloaded app - N26 — N26 Mobile Banking (impersonated brand)
Vulnerable versions: N/A -- N26's own app/infrastructure is not compromised; N26's brand and support identity are impersonated to social-engineer victims into installing Copybara
Remediation for Copybara Android RAT Delivered via Fake N26 Support Vishing
Immediate actions
- Block outbound connectivity to C2 IP 37.148.161.44 (TCP 52997/52998 and HTTP) at perimeter and mobile-device-management egress filters
- Sinkhole or block DNS resolution for n26portale.com and n26.com.de across managed networks and DNS security services
- Alert on any Android device newly granted Accessibility Service or Device Administrator permissions for a non-catalog package, especially io.smart.evolve or com.upy2dl.ptroa5
- Instruct customer-facing bank support teams to explicitly state N26 will never call customers requesting APK installation or 'certification update' sideloading
- Push a fraud alert to N26 customers describing the vishing script (fake support call, urgency around account security, request to install a security/certification app)
Workarounds
- Advise customers never to install banking-related apps or 'certificates' from links sent during an inbound phone call; only use the official Play Store listing
- If Copybara is suspected installed, use Android Safe Mode (which disables third-party Accessibility Services) to regain access to Settings > Apps and uninstall the dropper/payload
Longer-term hardening
- Deploy Mobile Threat Defense (MTD) / EDR with behavioral detection for Accessibility Service abuse and MQTT-based C2 beaconing on managed/BYOD Android fleets
- Enforce Google Play Protect and disable sideloading (unknown-sources installs) via MDM policy for corporate-enrolled devices used for banking
- Integrate call-center authentication (out-of-band verification, no unsolicited outbound install instructions) into banking support workflows to blunt TOAD-style social engineering
- Monitor for new brand-themed variants of this dropper family (icon/package/C2 rotation) given Copybara's history of frequent target-brand and infrastructure churn since 2021
Timeline of Copybara Android RAT Delivered via Fake N26 Support Vishing
- ThreatFabric names the Copybara Android RAT and splits it from the BRATA cluster into a distinct family alongside AmexTroll, based on shared B4A codebase origins.
- Copybara Android RAT first identified in the wild, active in Italian TOAD-style vishing campaigns against banking customers.
- ThreatFabric publishes 'BRATA - a tale of three families,' formally documenting the BRATA/AmexTroll/Copybara split.
- ThreatFabric publishes TOAD (telephone-oriented attack delivery) research showing vishing combined with Copybara targeting Italian banks, widely covered including by The Hacker News.
- Cleafy Labs tracks a new Copybara wave using the 'Mr. Robot' phishing panel and JOKER RAT C2, expanding targeting to Spanish and UK banking customers alongside Italy.
- A newer Copybara variant introduces MQTT-based command-and-control communication (documented by ThreatFabric/Cleafy TOAD-fraud reporting).
- Tinexta Cyber / d3Lab publish 'From Smishing and Vishing to Compromission,' dissecting Copybara's TOAD delivery chain against Italian banks.
- Zscaler ThreatLabz publishes a technical analysis of a newer Copybara variant, documenting a shift to MQTT-based C2 (port 52997) and cataloguing a 59-command capability set.
- D3 Lab publishes 'Inside an N26 Impersonation Campaign,' the original research documenting the Fake Control 1.0 / 'N26 Pdf' / 'Certificato N26' wave (GBHackers' 2026-07-30 writeup summarizes this report).
- Operators display a false N26 loading-screen overlay to occupy the victim while using Accessibility-driven input injection to open financial apps and attempt fraudulent transactions in the background.
- Infected devices establish MQTT command-and-control to 37.148.161.44 over TCP 52997 (topic commandsFromPC) and TCP 52998 (camera/MediaProjection channel).
- The dropper decrypts and loads WJcugJ.jar, which installs the Copybara payload (com.upy2dl.ptroa5, SHA-256 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412) and requests Accessibility Service, Device Administrator, camera, microphone, and SMS permissions.
- Victims are socially engineered into sideloading the outer dropper APK 'N26 Pdf' (io.smart.evolve, SHA-256 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a), disguised as a certification/security update.
- Victims are directed to fraudulent N26-branded phishing infrastructure (n26portale[.]com) to harvest account number, PIN, phone number, and security-question answers.
- Victims receive vishing calls impersonating N26 support, creating urgency around account security and directing them to attacker-controlled contact details (assistenza@n26.com.de).
- d3 Lab and Cyber Security News disclose a new N26-themed Copybara vishing campaign combining vishing calls, a live phishing panel, and a multi-stage Android dropper.
Update history for TL-2026-1804
- 2026-08-01 — Copybara Android RAT Abuses Accessibility Services in N26 Vishing Campaign ("Fake Control 1.0" / "Certificato N26"): What changed No escalation of severity/exploitability/status/attribution -- both reports agree HIGH/ACTIVE/ACTIVE/LOW. No new CVEs or CWEs (none apply). New indicators (33) 8 new phishing/distribution domains (app-link.cc, datos-cliente.com
Sources cited for Copybara Android RAT Delivered via Fake N26 Support Vishing
- Fake N26 Support Calls Deliver Copybara RAT
- Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control
- Technical Analysis of Copybara
- TOAD attacks: Vishing combined with Android banking malware now targeting Italian banks
- From Smishing and Vishing to Compromission: Dissecting Copybara's TOAD Delivery Chain
- Hackers Using Vishing to Trick Victims into Installing Android Banking Malware
- Copybara Malware Uses Vishing Tricks to Target Italian Banking Users
- BRATA (Malware Family)
Detection coverage for TL-2026-1804
As of 2026-08-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1804 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.