N26 Phishing Campaign Deploys Copybara RAT via Vishing Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new fraud campaign is targeting Android banking users by impersonating N26 support staff through voice phishing. Victims are misled into believing their accounts require urgent verification or device updates. Attackers utilize the Copybara Android RAT to gain remote control over banking apps by exploiting Android's Accessibility services. The campaign is particularly active in Italy, where attackers leverage real notifications from the N26 app to build trust. This multi-stage attack involves vishing and a sophisticated Android dropper, leading to keylogging and screen streaming capabilities. As of July 30, 2026, the campaign is ongoing, affecting numerous Android users who trust N26. Security professionals are advised to remain vigilant against such social engineering tactics.
Key Points: • Fraud campaign targets Android banking users via fake N26 support calls. • Copybara RAT is used for remote control of banking apps through Accessibility services. • The attack chain includes vishing and a multi-stage Android dropper.