# Copybara Android RAT Delivered via Fake N26 Support Vishing Calls

> A fraud campaign impersonates N26 bank support via vishing calls to steer victims through a live phishing panel and a trojanized 'certification update' APK that installs the Copybara Android RAT. Copybara abuses Accessibility Services for full remote device control -- keylogging, screen/microphone/camera capture, SMS and contact theft, and additional APK installation -- enabling banking-app account takeover.

- **Published:** 2026-08-01T00:00:00Z
- **Last reviewed:** 2026-08-01T12:03:20.984Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1804
- **ID:** TL-2026-1804
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 55 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Researchers at d3 Lab, in analysis shared with Cyber Security News and published 2026-07-30, documented a coordinated fraud operation targeting customers of the German neobank N26. The campaign chains voice phishing (vishing), a real-time phishing control panel, and a multi-stage Android dropper to achieve full remote control of victim devices via abused Accessibility Services.

The attack begins with a credential-harvesting phishing page (n26portale[.]com) that collects account number, PIN, telephone number, and security-question answers -- consistent with the Telephone-Oriented Attack Delivery (TOAD) tradecraft d3Lab/Tinexta Cyber previously documented against Italian banks. Victims are then called by an operator or automated message impersonating N26 support (using fraudulent contact infrastructure at n26[.]com[.]de, email assistenza@n26.com.de), who creates urgency around 'account security' and a required 'certification update,' and walks the victim through sideloading an APK outside the Play Store.

The outer dropper, packaged as io.smart.evolve and labeled 'N26 Pdf' (also referenced internally as 'Certificato N26'), decrypts and loads an embedded JAR (marker filename WJcugJ.jar) which in turn installs the Copybara payload (com.upy2dl.ptroa5). The dropper/payload combination uses structural anomalies -- conflicting ZIP compression metadata, extreme-length asset paths, random Unicode path components, and resource collisions -- to defeat conventional static-analysis tooling. During installation the victim is repeatedly prompted (notification harassment) to enable Accessibility Service and Device Administrator permissions; once granted, Copybara transforms the Accessibility API into a full remote-control surface: simulated taps/swipes/text entry, UI-hierarchy extraction, keylogging, real-time screen streaming, camera (front/rear) and microphone capture via MediaProjection, SMS/contact/call-log theft, installed-app enumeration, and silent installation of additional APKs. The malware also temporarily installs local VPN rules that researchers believe interfere with Google Play Protect scanning during install, and abuses Accessibility-granted control of the Settings app to block victims from reaching the uninstall screen.

Command and control runs over MQTT to 37[.]148[.]161[.]44: TCP 52997 carries the primary command channel (topic commandsFromPC / commands_FromPC, exfiltrating to sub-topics such as med, divap_topc, and Device_Calls_Logs_Save), while TCP 52998 carries higher-volume camera and MediaProjection screen data; an HTTP service on the same IP delivers overlay HTML and lock-screen content. During active fraud, operators display a false N26 'loading screen' overlay via WebView to occupy the victim while using Accessibility-driven input injection in the background to open financial apps, read incoming SMS one-time passcodes, and attempt fraudulent transactions.

Copybara is not a novel family: it has been active since at least November 2021 in Italian TOAD-style vishing campaigns targeting banking and (per Zscaler ThreatLabz) cryptocurrency-exchange credentials, is built on the B4A/B4X (Basic4Android) legitimate app-development framework, and shares banking-trojan tradecraft and MQTT-based C2 architecture with the BRATA malware lineage without being a direct BRATA derivative. This N26-themed wave, first surfaced 2026-07-30, is the newest observed target-brand rotation of an established, actively maintained TOAD delivery chain. No CVE applies -- the campaign relies entirely on social engineering and Android Accessibility Service abuse, not a software vulnerability.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1583.001 Domains
- T1583.004 Server
- T1587.001 Malware
- T1660 Phishing
- T1476 Deliver Malicious App via Other Means
- T1444 Masquerade as Legitimate Application
- T1407 Download New Code at Runtime
- T1624.001 Broadcast Receivers
- T1541 Foreground Persistence
- T1626.001 Device Administrator Permissions
- T1628.001 Suppress Application Icon
- T1628.002 User Evasion
- T1629.001 Prevent Application Removal
- T1406.002 Software Packing
- T1417.001 Keylogging
- T1417.002 GUI Input Capture
- T1418 Software Discovery
- T1426 System Information Discovery
- T1422 System Network Configuration Discovery
- T1420 File and Directory Discovery
- T1512 Video Capture
- T1429 Audio Capture
- T1636.002 Call Log
- T1636.003 Contact List
- T1636.004 SMS Messages
- T1533 Data from Local System
- T1414 Clipboard Data
- T1437 Application Layer Protocol
- T1646 Exfiltration Over C2 Channel
- T1516 Input Injection
- T1582 SMS Control
- T1598.004 Spearphishing Voice
- T1204.002 Malicious File
- T1398 Boot or Logon Initialization Scripts
- T1633.001 System Checks
- T1630.003 Disguise Root/Jailbreak Indicators
- T1430 Location Tracking
- T1509 Non-Standard Port

## Sources

- [Fake N26 Support Calls Deliver Copybara RAT](https://cybersecuritynews.com/fake-n26-support-calls-copybara-rat/)
- [Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control](https://gbhackers.com/copybara-abuses-android/)
- [Technical Analysis of Copybara](https://www.zscaler.com/blogs/security-research/technical-analysis-copybara)
- [TOAD attacks: Vishing combined with Android banking malware now targeting Italian banks](https://www.threatfabric.com/blogs/toad-fraud)
- [From Smishing and Vishing to Compromission: Dissecting Copybara's TOAD Delivery Chain](https://www.tinextacyber.com/wp-content/uploads/2024/07/2406-CopyBara-Android.pdf)
- [Hackers Using Vishing to Trick Victims into Installing Android Banking Malware](https://thehackernews.com/2022/10/hackers-using-vishing-tactics-to-trick.html)
- [Copybara Malware Uses Vishing Tricks to Target Italian Banking Users](https://social.cyware.com/news/copybara-malware-uses-vishing-tricks-to-target-italian-banking-users-e8f2144f)
- [BRATA (Malware Family)](https://malpedia.caad.fkie.fraunhofer.de/details/apk.brata)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1804
