Threat reportMalwareTL-2026-1804

Copybara Android RAT Delivered via Fake N26 Support Vishing Calls

highACTIVE

Copybara Android RAT Delivered via Fake N26 Support Vishing (TL-2026-1804), also tracked as Certificato N26 Campaign, is a high-severity malware campaign, first published 2026-08-01. It has no confirmed attribution, affects Google Android OS, maps to 39 MITRE ATT&CK techniques (T1204.002, T1398, T1406.002), and is covered by 9 detection rules and 55 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
39MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
55Indicators of compromise

Key facts for TL-2026-1804

Threat ID
TL-2026-1804
Also known as
Certificato N26 Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, banking, digital banking, consumer banking
Target regions
italy, spain, Europe
Detection rules
9
Indicators of compromise
55
Updates
2026-08-01 · revalidated 1× · latest source

Malware and tooling in Copybara Android RAT Delivered via Fake N26 Support Vishing

Malware and tooling: BRATA, BRATA - S1094, N26 Pdf, B4A (Basic4Android), MQTT

How Copybara Android RAT Delivered via Fake N26 Support Vishing works

A fraud campaign impersonates N26 bank support via vishing calls to steer victims through a live phishing panel and a trojanized 'certification update' APK that installs the Copybara Android RAT. Copybara abuses Accessibility Services for full remote device control -- keylogging, screen/microphone/camera capture, SMS and contact theft, and additional APK installation -- enabling banking-app account takeover.

Researchers at d3 Lab, in analysis shared with Cyber Security News and published 2026-07-30, documented a coordinated fraud operation targeting customers of the German neobank N26. The campaign chains voice phishing (vishing), a real-time phishing control panel, and a multi-stage Android dropper to achieve full remote control of victim devices via abused Accessibility Services.

The attack begins with a credential-harvesting phishing page (n26portale[.]com) that collects account number, PIN, telephone number, and security-question answers -- consistent with the Telephone-Oriented Attack Delivery (TOAD) tradecraft d3Lab/Tinexta Cyber previously documented against Italian banks. Victims are then called by an operator or automated message impersonating N26 support (using fraudulent contact infrastructure at n26[.]com[.]de, email assistenza@n26.com.de), who creates urgency around 'account security' and a required 'certification update,' and walks the victim through sideloading an APK outside the Play Store.

The outer dropper, packaged as io.smart.evolve and labeled 'N26 Pdf' (also referenced internally as 'Certificato N26'), decrypts and loads an embedded JAR (marker filename WJcugJ.jar) which in turn installs the Copybara payload (com.upy2dl.ptroa5). The dropper/payload combination uses structural anomalies -- conflicting ZIP compression metadata, extreme-length asset paths, random Unicode path components, and resource collisions -- to defeat conventional static-analysis tooling. During installation the victim is repeatedly prompted (notification harassment) to enable Accessibility Service and Device Administrator permissions; once granted, Copybara transforms the Accessibility API into a full remote-control surface: simulated taps/swipes/text entry, UI-hierarchy extraction, keylogging, real-time screen streaming, camera (front/rear) and microphone capture via MediaProjection, SMS/contact/call-log theft, installed-app enumeration, and silent installation of additional APKs. The malware also temporarily installs local VPN rules that researchers believe interfere with Google Play Protect scanning during install, and abuses Accessibility-granted control of the Settings app to block victims from reaching the uninstall screen.

Command and control runs over MQTT to 37[.]148[.]161[.]44: TCP 52997 carries the primary command channel (topic commandsFromPC / commands_FromPC, exfiltrating to sub-topics such as med, divap_topc, and Device_Calls_Logs_Save), while TCP 52998 carries higher-volume camera and MediaProjection screen data; an HTTP service on the same IP delivers overlay HTML and lock-screen content. During active fraud, operators display a false N26 'loading screen' overlay via WebView to occupy the victim while using Accessibility-driven input injection in the background to open financial apps, read incoming SMS one-time passcodes, and attempt fraudulent transactions.

Copybara is not a novel family: it has been active since at least November 2021 in Italian TOAD-style vishing campaigns targeting banking and (per Zscaler ThreatLabz) cryptocurrency-exchange credentials, is built on the B4A/B4X (Basic4Android) legitimate app-development framework, and shares banking-trojan tradecraft and MQTT-based C2 architecture with the BRATA malware lineage without being a direct BRATA derivative. This N26-themed wave, first surfaced 2026-07-30, is the newest observed target-brand rotation of an established, actively maintained TOAD delivery chain. No CVE applies -- the campaign relies entirely on social engineering and Android Accessibility Service abuse, not a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1804

Execution

T1204.002 Malicious File

Persistence

T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence

defense-evasion

T1406.002 Software Packing; T1407 Download New Code at Runtime; T1628.001 Suppress Application Icon; T1628.002 User Evasion; T1629.001 Prevent Application Removal; T1630.003 Disguise Root/Jailbreak Indicators; T1633.001 System Checks

Collection

T1414 Clipboard Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1533 Data from Local System; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages

collection

T1417.001 Keylogging

credential-access

T1417.002 GUI Input Capture

Discovery

T1418 Software Discovery; T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery

command-and-control

T1437 Application Layer Protocol; T1509 Non-Standard Port

initial-access

T1444 Masquerade as Legitimate Application; T1476 Deliver Malicious App via Other Means; T1660 Phishing

Impact

T1516 Input Injection; T1582 SMS Control

Resource Development

T1583.001 Domains; T1583.004 Server; T1587.001 Malware

Reconnaissance

T1598 Phishing for Information; T1598.004 Spearphishing Voice

persistence

T1624.001 Broadcast Receivers

privilege-escalation

T1626.001 Device Administrator Permissions

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Copybara Android RAT Delivered via Fake N26 Support Vishing

  • Google — Android OS
    Vulnerable versions: Any Android version where sideloading (install from unknown sources) is permitted and Accessibility Service can be granted to a sideloaded app
  • N26 — N26 Mobile Banking (impersonated brand)
    Vulnerable versions: N/A -- N26's own app/infrastructure is not compromised; N26's brand and support identity are impersonated to social-engineer victims into installing Copybara

Remediation for Copybara Android RAT Delivered via Fake N26 Support Vishing

Immediate actions

  • Block outbound connectivity to C2 IP 37.148.161.44 (TCP 52997/52998 and HTTP) at perimeter and mobile-device-management egress filters
  • Sinkhole or block DNS resolution for n26portale.com and n26.com.de across managed networks and DNS security services
  • Alert on any Android device newly granted Accessibility Service or Device Administrator permissions for a non-catalog package, especially io.smart.evolve or com.upy2dl.ptroa5
  • Instruct customer-facing bank support teams to explicitly state N26 will never call customers requesting APK installation or 'certification update' sideloading
  • Push a fraud alert to N26 customers describing the vishing script (fake support call, urgency around account security, request to install a security/certification app)

Workarounds

  • Advise customers never to install banking-related apps or 'certificates' from links sent during an inbound phone call; only use the official Play Store listing
  • If Copybara is suspected installed, use Android Safe Mode (which disables third-party Accessibility Services) to regain access to Settings > Apps and uninstall the dropper/payload

Longer-term hardening

  • Deploy Mobile Threat Defense (MTD) / EDR with behavioral detection for Accessibility Service abuse and MQTT-based C2 beaconing on managed/BYOD Android fleets
  • Enforce Google Play Protect and disable sideloading (unknown-sources installs) via MDM policy for corporate-enrolled devices used for banking
  • Integrate call-center authentication (out-of-band verification, no unsolicited outbound install instructions) into banking support workflows to blunt TOAD-style social engineering
  • Monitor for new brand-themed variants of this dropper family (icon/package/C2 rotation) given Copybara's history of frequent target-brand and infrastructure churn since 2021

Timeline of Copybara Android RAT Delivered via Fake N26 Support Vishing

  • ThreatFabric names the Copybara Android RAT and splits it from the BRATA cluster into a distinct family alongside AmexTroll, based on shared B4A codebase origins.
  • Copybara Android RAT first identified in the wild, active in Italian TOAD-style vishing campaigns against banking customers.
  • ThreatFabric publishes 'BRATA - a tale of three families,' formally documenting the BRATA/AmexTroll/Copybara split.
  • ThreatFabric publishes TOAD (telephone-oriented attack delivery) research showing vishing combined with Copybara targeting Italian banks, widely covered including by The Hacker News.
  • Cleafy Labs tracks a new Copybara wave using the 'Mr. Robot' phishing panel and JOKER RAT C2, expanding targeting to Spanish and UK banking customers alongside Italy.
  • A newer Copybara variant introduces MQTT-based command-and-control communication (documented by ThreatFabric/Cleafy TOAD-fraud reporting).
  • Tinexta Cyber / d3Lab publish 'From Smishing and Vishing to Compromission,' dissecting Copybara's TOAD delivery chain against Italian banks.
  • Zscaler ThreatLabz publishes a technical analysis of a newer Copybara variant, documenting a shift to MQTT-based C2 (port 52997) and cataloguing a 59-command capability set.
  • D3 Lab publishes 'Inside an N26 Impersonation Campaign,' the original research documenting the Fake Control 1.0 / 'N26 Pdf' / 'Certificato N26' wave (GBHackers' 2026-07-30 writeup summarizes this report).
  • Operators display a false N26 loading-screen overlay to occupy the victim while using Accessibility-driven input injection to open financial apps and attempt fraudulent transactions in the background.
  • Infected devices establish MQTT command-and-control to 37.148.161.44 over TCP 52997 (topic commandsFromPC) and TCP 52998 (camera/MediaProjection channel).
  • The dropper decrypts and loads WJcugJ.jar, which installs the Copybara payload (com.upy2dl.ptroa5, SHA-256 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412) and requests Accessibility Service, Device Administrator, camera, microphone, and SMS permissions.
  • Victims are socially engineered into sideloading the outer dropper APK 'N26 Pdf' (io.smart.evolve, SHA-256 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a), disguised as a certification/security update.
  • Victims are directed to fraudulent N26-branded phishing infrastructure (n26portale[.]com) to harvest account number, PIN, phone number, and security-question answers.
  • Victims receive vishing calls impersonating N26 support, creating urgency around account security and directing them to attacker-controlled contact details (assistenza@n26.com.de).
  • d3 Lab and Cyber Security News disclose a new N26-themed Copybara vishing campaign combining vishing calls, a live phishing panel, and a multi-stage Android dropper.

Update history for TL-2026-1804

Sources cited for Copybara Android RAT Delivered via Fake N26 Support Vishing

Detection coverage for TL-2026-1804

As of 2026-08-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1804 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
55 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats