Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT

,

An active fraud campaign targeting users in Italy combines voice phishing, a real-time phishing control panel, and an Android remote access trojan. The operation begins with a phone call from someone impersonating N26 support and ends with the attacker controlling financial applications on the victim’s phone.

The malicious application is presented as a device certification component. Behind that pretext is a multistage Android dropper whose embedded payload belongs to the Copybara family.

This is not simply a credential-harvesting website. It is a human-operated workflow designed to move the attacker from social engineering to on-device fraud.

The campaign in context

The campaign was publicly highlighted by ShadowOpCode on X, who referenced a detailed victim report on Reddit.

According to the report, the victim first received several calls. An automated message claimed that additional account verification was required, after which a purported N26 representative guided the victim through a device “certification” process.

The operator used trusted real messages already visible in the banking application to reinforce the story. The victim was then moved outside the bank’s trusted communication channel and instructed to contact a fraudulent support address.

The reply led to an N26-themed login page hosted on an attacker-controlled domain. After the victim entered credentials, the site offered an Android package and the operator instructed the victim to enable Accessibility, location, device-control, and other invasive permissions.

Once those permissions were granted, an N26-branded white screen and loading indicator covered the display. The victim reported that settings were changed and transactions were attempted across several financial applications while that cover remained visible.

A phishing site operated in real time

The phishing site is part of a web-based phishing control system identified with high confidence as Fake Control 1.0 or AdminLTE. The identification is based on the structure of the victim URL, the server-side layout, the exposed primary and backup SQLite databases, and the dedicated malware-delivery channel.

The phishing site was also observed delivering the Android package analyzed in this report.

What Fake Control 1.0 does

Fake Control 1.0 uses PHP, SQLite, JavaScript, and an administrative interface based on AdminLTE. AdminLTE itself is a legitimate and widely used dashboard template; its presence alone is not a malicious family marker.

The distinctive evidence lies in the workflow implemented around it. The kit maintains victim records, updates the operator dashboard every few seconds, collects credentials and one-time codes across multiple stages, and allows the operator to control what the victim sees next.

The available commands include messages, token validation and invalidation, transaction-cancellation lures, and an APK download action. This turns the page into an interactive social-engineering console rather than a static login clone.

The kit stores operational data in SQLite and keeps a separate backup. The administrative components provide access to individual victim sessions, aggregate access logs, and export functions. Portuguese identifiers such as senha, acesso, gerente, and enviarComando indicate the development language or ecosystem of the kit, but they do not establish the nationality or location of the campaign operators.

The victim URL contains separate values for verification, session identification, and attempt tracking. Those parameters match the flow described in the Fake Control material and explain how a phone operator can follow one victim in real time while presenting different instructions or download actions.

The Android delivery stage

The outer application calls itself N26 Pdf and uses the package name io.smart.evolve. It presents an update screen for a component named Certificato N26.

The dropper copies an embedded package, asks Android for permission to install applications from an unknown source, and invokes the standard PackageInstaller flow. A foreground observer checks the permission state every 800 milliseconds and continues as soon as installation is allowed.

The dropper also creates a local per-application VPN for com.android.vending, the Google Play Store package. It routes IPv4 and IPv6 traffic into a local TUN interface and discards the packets for 240 seconds.

Strings in the code refer to a ten-second block, but the implemented constant is 240,000 milliseconds. The most plausible purpose is to disrupt Play Store or Play Protect communication during the installation window.

Structural anti-analysis

Both the outer dropper and the embedded payload contain deliberate ZIP inconsistencies. apkInspector identified conflicting compression methods between local headers and the central directory.

The outer APK contains random Unicode path components, large extra fields, and an asset path 2,441 bytes long. Conventional tools may reject the file or fail when creating the directory structure.

The embedded APK adds another technique. Seventy resources are placed below file-like prefixes such as classes.dex, AndroidManifest.xml, and resources.arsc, creating collisions between files and directories.

These anomalies are evidence of anti-static-analysis engineering, but they are not treated as malicious proof on their own. The malicious classification rests on the loader, installation behavior, command-and-control configuration, and RAT capabilities.

Recovering the hidden stages

The outer application class, biz.include.seat.Lbachelorcycle, extracts a JAR hidden at the end of the extreme asset path. It processes the asset and decrypts the result using RC4.

The recovered JAR contains a DEX that implements the actual dropper logic. That loader locates assets/base.apk, presents its label and icon to the victim, and installs it.

The reconstructed chain is: N26 Pdf dropper > Obfuscated Application class > Encrypted WJcugJ.jar > RC4 decryption > Dynamic loader DEX > Embedded base.apk > Copybara payload

The most important hashes are:

ArtifactSHA-256
Outer dropper464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a
Decrypted loader JAR0475a46c70d8671322d39392c55d404b6d8f4de34090f0373244cef52ae55708
Loader DEXb88668403a6dabe4867573fc23c11ce937291f6aab7e65e8261b4c967ab2e68c
Embedded payload APK7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412

The embedded Copybara payload

The embedded APK is labelled Certificato N26 and uses package com.upy2dl.ptroa5. Its MD5 is e792fedfd11d56a9ad68e6d407b9a09e, and its SHA-256 is 7cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412.

The payload is attributed to Copybara with high confidence. The attribution is based on its B4A/B4X codebase, MQTT channels on ports 52997 and 52998, the commands_FromPC topic, B4X-serialized command maps, server-side injection handling, and command vocabulary.

The payload declares 18 activities, 16 services, 19 receivers, and a provider. Its most important components include an Accessibility service, a notification listener, a device-administrator receiver, SMS handlers, microphone and MediaProjection services, and boot persistence.

Android documents that an Accessibility service can receive interface events, inspect active-window content, and act on behalf of a user. These capabilities are intended for assistive technology, but Copybara repurposes them as a remote-control channel.

Why Battery Cleaner Pro is inside the payload

The presence of Battery Cleaner Pro is not evidence of a separate benign application bundled by accident. It is the payload’s default local decoy interface.

The payload contains six localized HTML pages for English, Italian, German, Spanish, French, and Portuguese. It also includes dedicated battery, boost, cleaner, cooler, and application icons.

At startup, the main activity reads the phone language and selects the matching pg-<language>.html file. If no supported language is found, it falls back to the English page.

The selected page is loaded full screen in a WebView. The activity also checks whether the malicious Accessibility service is enabled and prompts the user to open the installed-services settings when it is not.

The interface claims to display battery charge, temperature, free memory, battery-draining applications, and junk files. Those values are hard-coded in the HTML. The English page always shows values such as 72 percent battery, 38 degrees Celsius, 1.8 GB of free RAM, and fixed cache sizes.

The “clean and optimize” control is part of the static presentation and is not backed by a genuine cleaning engine in the page. Battery Cleaner Pro therefore provides cover, not device maintenance.

This decoy serves several purposes. It gives the payload a generic identity after the N26-themed installation stage, provides a plausible reason for battery-related settings and persistent background execution, and keeps a harmless-looking screen available while the Accessibility-controlled service operates.

The multilingual pages also make the payload reusable. The same Copybara build can be distributed through different brands or campaigns while retaining a neutral utility interface on the infected device.

The package includes a design.txt file identifying the decoy as Battery Cleaner Pro version 2.1.4, build 114. Those values describe the embedded presentation and must not be confused with the Android package version declared in the manifest.

Remote-control capabilities

The MQTT dispatcher contains 64 commands. Copybara can drive clicks, swipes, global actions, and text entry through Accessibility. It can also capture the visible UI hierarchy and text from focused fields.

The malware implements keylogging, screen streaming, MediaProjection capture, camera access, and microphone recording. A secondary MQTT channel is used for higher-volume camera and screen activity.

SMS messages can be read, sent, deleted, and exfiltrated. Contacts, call logs, installed applications, device identifiers, language, battery state, and other telemetry can also be collected.

The malware can open URLs, download arbitrary files, install additional APKs, launch or remove applications, hide its icon, suppress notifications, and interfere with uninstallation.

These capabilities explain the victim’s observations. The white N26 screen can conceal attacker activity, while Accessibility drives the real banking applications underneath. Biometric security does not need to be technically bypassed when the victim is manipulated into approving a legitimate system prompt without seeing its true context.

The reported device reset is compatible with the malware’s device-administration and destructive-control surface, but the available static evidence does not tie that specific event to one confirmed command.

Two control layers

The campaign uses two distinct control systems.

Fake Control 1.0 operates the social-engineering phase. It tracks the victim’s web session, collects credentials and authentication data, allows the operator to change the page state, and delivers the Android dropper.

Copybara takes over after installation. It uses a hardcoded IP address for MQTT commands and remote content.

The Android configuration initializes the C2 address directly as 37[.]148[.]161[.]44. The primary MQTT channel uses TCP port 52997, while camera and MediaProjection components use port 52998.

The client subscribes to commands_FromPC with QoS 1. Registration is sent through RegisterMyDevice, and the device identifier is replaced with the Android ID.

HTTP services on the same IP host overlay templates, images, and lock-screen content. No dead drop, domain-based bootstrap, CDN, or reverse proxy was found in the Android configuration.

Server-side overlays and observed targets

The complete overlay list is not embedded in the APK. Copybara receives an inj structure from the server containing an application package and a template filename, then retrieves the corresponding content from the remote repository.

This design allows operators to change targets without rebuilding the APK. It also means that static analysis cannot recover a complete campaign target list.

N26 is confirmed as the distribution lure. The victim report also mentions Poste, Intesa Sanpaolo, and Microsoft Authenticator during the incident. These should be described as observed applications in one victim case, not as a complete embedded overlay list.

An earlier Reddit report from May 2026 described a similar N26 vishing workflow, applications named Certificato N26 and Modulo N26, an apparent maintenance period, cross-account theft, and a final device reset.

The shared application name and operational pattern support a same-campaign or shared-playbook relationship with medium-to-high confidence. Binary identity cannot be established because the APK from the earlier incident is not available for hashing.

Indicators of compromise

Network indicators are defanged to prevent accidental access. Shared providers and their full address ranges should not be blocked based on this campaign.

TypeIndicatorRole
SHA-256464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4aMalicious dropper
SHA-2567cf365d61e59d5c3dd50295b1d5a0c360da9eba1b4dc00cdc0f1ceee4a5cc412Copybara payload
Packageio.smart.evolveDropper package
Packagecom.upy2dl.ptroa5Payload package
Domainn26portale[.]comPhishing and Fake Control infrastructure
Domainn26[.]com[.]deFraudulent support-mail infrastructure
Emailassistenza@n26[.]com[.]deCampaign contact address
IPv437[.]148[.]161[.]44Copybara C2 and content host
MQTT topiccommands_FromPCCommand channel
FilenameWJcugJ.jarEncrypted loader marker

The paths to exposed databases and to the live APK are deliberately excluded. They add no defensive value to a public article beyond the hashes and could expose victim data or facilitate further downloads.

Conclusion

This campaign is effective because each stage supports the next.

The phone operator creates urgency and keeps the victim engaged. Fake Control 1.0 gives that operator a real-time view of the phishing session and a controlled path for delivering malware. The dropper then handles installation and anti-analysis, while Copybara provides the Accessibility, overlay, screen-control, and data-theft capabilities needed for on-device fraud.

Battery Cleaner Pro completes the deception. It gives the installed payload a generic, multilingual utility interface while the malicious service operates in the background.

The white N26 loading screen is not a security process. It is the curtain behind which the attack takes place.

This research was conducted for defensive purposes.

N26 and the other brands mentioned in this article are victims or affected parties. They are not associated with the operators of this campaign.

D3Lab Srl unipersonale – P.IVA IT01865450496 – Italy – Phone: +3905861946434