ThreatCluster

N26 Phishing Campaign Deploys Copybara RAT via Vishing Attacks

First seen 30 Jul 2026, 08:49 UTC CybersecuritynewsGbhackers 74% similarity 65

Article Content

Browse articles
ThreatCluster

A new fraud campaign is targeting Android banking users by impersonating N26 support staff through voice phishing. Victims are misled into believing their accounts require urgent verification or device updates. Attackers utilize the Copybara Android RAT to gain remote control over banking apps by exploiting Android's Accessibility services. The campaign is particularly active in Italy, where attackers leverage real notifications from the N26 app to build trust. This multi-stage attack involves vishing and a sophisticated Android dropper, leading to keylogging and screen streaming capabilities. As of July 30, 2026, the campaign is ongoing, affecting numerous Android users who trust N26. Security professionals are advised to remain vigilant against such social engineering tactics.

Key Points: • Fraud campaign targets Android banking users via fake N26 support calls. • Copybara RAT is used for remote control of banking apps through Accessibility services. • The attack chain includes vishing and a multi-stage Android dropper.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
Fraud campaign identified
A new N26-themed fraud campaign using Copybara RAT was reported, targeting Android users in Italy.
Gbhackers
2026-07-30
Voice phishing initiated
Attackers impersonate N26 support to trick victims into granting access to their banking apps.
Cybersecuritynews

Community

Browse all →