A sophisticated fraud operation targeting N26 users in Italy combines voice phishing with live phishing and remote access trojans to steal banking applications. Victims are misled into believing their accounts or devices need urgent verification, leading them through a fake "device certification" process that uses legitimate messages from the app itself. The control panel maintains victim records, gathers credentials and one-time passcodes, refreshes operator dashboards every few seconds, and allows criminals to modify what's shown to individual victims.
N26 Support Scam Uses Remote Access Tool (RAT) (Source: d3lab) Available actions include sending messages, validating or rejecting authentication tokens, displaying transaction-cancellation lures, and triggering APK downloads. It routes and discards traffic for 240,240,240 seconds, potentially disrupting Play Store or Play Protect checks during installation.
N26 Support Scam Deploys Remote Access Tool (RAT) (Source: d3lab) Both the dropper and embedded payload feature malformed ZIP structures, unusual Unicode paths, oversized fields, and file-directory collisions. The final payload, identified with high confidence as Copybara, uses the package name com.upy2dl.ptroa5 and masquerades as "Certificato N26." It contains a B4A/B4X codebase and communicates with command-and-control infrastructure through MQTT.












