A recent report by D3Lab highlights a fraud campaign targeting N26 banking customers in Italy, employing a vishing attack that begins with a fraudulent phone call. The scam utilizes a Copybara Android RAT, which is delivered through a fake support interaction and leads to a malicious APK installation on the victim's device. Key capabilities of the malware include remote control, keystroke logging, and SMS theft.
The operators use a dynamic phishing panel to interact with victims in real-time, collecting sensitive data. To defend against such attacks, users are advised to avoid installing apps requested during unsolicited calls and to only download apps from official sources.