Skip to content
ThreatCluster

N26 Phishing Campaign Deploys Copybara RAT via Vishing Attacks

First seen 30 Jul 2026, 08:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • Fraud campaign targets Android banking users via fake N26 support calls.
  • Copybara RAT is used for remote control of banking apps through Accessibility services.
  • The attack chain includes vishing and a multi-stage Android dropper.

A new fraud campaign is targeting Android banking users by impersonating N26 support staff through voice phishing. Victims are misled into believing their accounts require urgent verification or device updates. Attackers utilize the Copybara Android RAT to gain remote control over banking apps by exploiting Android's Accessibility services. The campaign is particularly active in Italy, where attackers leverage real notifications from the N26 app to build trust. This multi-stage attack involves vishing and a sophisticated Android dropper, leading to keylogging and screen streaming capabilities. As of July 30, 2026, the campaign is ongoing, affecting numerous Android users who trust N26. Security professionals are advised to remain vigilant against such social engineering tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 52d ago How this analysis works

Timeline

2026-07-30
Fraud campaign identified
A new N26-themed fraud campaign using Copybara RAT was reported, targeting Android users in Italy.
Gbhackers
2026-07-30
Voice phishing initiated
Attackers impersonate N26 support to trick victims into granting access to their banking apps.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track Copybara and N26 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed