Copybara is an Android banking remote-access trojan active since the second half of 2021, primarily targeting customers of Italian financial institutions. It is used for on-device fraud and abuses Android Accessibility Services to let operators remotely interact with infected devices, including opening applications, performing taps and swipes, entering text, scrolling, blocking or uninstalling applications, and installing further applications. It supports screenshot-based screen streaming, screen capture, overlays that conceal fraudulent activity, and remote factory reset. Copybara uses institution-specific overlays and dynamically generated forms to collect personally identifiable information, and can use Accessibility event logging for broad keylogging. Companion functionality can monitor SMS messages to capture banking two-factor authentication codes. Campaigns commonly combine bank-themed phishing pages with SMS phishing and telephone-oriented attack delivery: victims are called by criminals impersonating bank support personnel and persuaded to sideload a purported security application and grant Accessibility permissions. Copybara has sometimes been incorrectly grouped with BRATA, but is distinct from the original BRATA family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims receive a SMS from their bank with a link, followed by a call by the operator to guide them through the process.
The campaign reportedly starts with repeated calls from an automated message or a person claiming to represent N26 support. The caller creates urgency around account security, then moves the target away from trusted banking channels and toward attacker-controlled contact details.
This feature is the key to perform On-Device Fraud (ODF) once PIIs are exfiltrated, and is implmented in both cases using libraries publicly available on the B4A forum.
The campaign discovered by our analysts is targeting multiple Italian banks and their customers. It involves multiple phishing sites impersonating several Italian financial services and anti-fraud offices.
Copybara is distributed via SMiShing . Victims receive a SMS from their bank with a link, followed by a call by the operator to guide them through the process.
The caller, who purports to be a support agent for the bank, instructs the individual on the other end of the call to install a security app and grant it extensive permissions, when, in reality, it's malicious software intended to gain remote access or conduct financial fraud.
This feature is the key to perform On-Device Fraud (ODF) once PIIs are exfiltrated, and is implmented in both cases using libraries publicly available on the B4A forum.
This feature is the key to perform On-Device Fraud (ODF) once PIIs are exfiltrated, and is implmented in both cases using libraries publicly available on the B4A forum.
The first campaign was quite limited in size, and was followed a few months after, between the end of 2021 and the beginning of 2022, by more refined campaigns, still targeting Italy, posing as an array of security related applications.
Copybara's RAT capabilities are powered by abusing the operating system's accessibility services API to gather sensitive information and even uninstall the downloader app to reduce its forensic footprint.
This feature is the key to perform On-Device Fraud (ODF) once PIIs are exfiltrated, and is implmented in both cases using libraries publicly available on the B4A forum.
The white N26-branded screen reported by a victim is especially concerning because it can hide activity happening underneath. Rather than breaking biometric protections, attackers may rely on victims to approve a real prompt without seeing what is actually being authorized.
Another quite unique feature recently introduced by authors is the ability to dynamically build fake input forms and show it to victims. Actors are able to specify arbitrary input fields, text labels, check boxes and collect even more data from victims. | While the TA is connected to infected device, Copybara shows a fake overlay that is semi-transparent to cover the actions of the cyber criminals. | All phishing sites seen in the campaign request similar set of personal data: account number, PIN code, telephone number. Our team noticed that, in some cases, cybercriminals request victims to choose secret questions and answers that were set during the registration process with the bank as second factor of authentication.
The main Copybara application is able to download an external module, capable of perfoming Accessibility event logging, a feature that is extremely important when implementing On-Device Fraud, as it allows criminal to have a full visibility and actionability on all the UI elements on the victim’s devices, as well as allowing to implement a very inclusive keylogging mechanism.
Another quite unique feature recently introduced by authors is the ability to dynamically build fake input forms and show it to victims. Actors are able to specify arbitrary input fields, text labels, check boxes and collect even more data from victims. | While the TA is connected to infected device, Copybara shows a fake overlay that is semi-transparent to cover the actions of the cyber criminals. | All phishing sites seen in the campaign request similar set of personal data: account number, PIN code, telephone number. Our team noticed that, in some cases, cybercriminals request victims to choose secret questions and answers that were set during the registration process with the bank as second factor of authentication.
The main Copybara application is able to download an external module, capable of perfoming Accessibility event logging, a feature that is extremely important when implementing On-Device Fraud, as it allows criminal to have a full visibility and actionability on all the UI elements on the victim’s devices, as well as allowing to implement a very inclusive keylogging mechanism.
Whenever the overlay is triggered, the bot automatically opens a WebView with the corresponding phishing overlay to steal the wanted PII.
Attackers communicate with infected phones through MQTT services hosted on a hard-coded server. The campaign uses one channel for commands and another for higher-volume activities such as camera access and screen capture, giving operators a direct route to manipulate the device remotely.
the C2 server sends a specific command/action to perform and Copybara handles it with the help of its Accessibility engine.
both generate a series of screenshots every few milliseconds, which then send to the C2 to mimic a real-time video stream. In this way, operators on the other side can interact with the device remotely, allowing criminals to perform actions directly on the infected device.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile banking malware family among the three families collectively targeting 60% of global financial applications.
Android remote access trojan used in a fraud campaign targeting banking users. It is delivered after voice phishing and credential theft, abuses Android Accessibility permissions, and enables remote control of the victim device, including taps, swipes, text entry, screen capture/streaming, keylogging, SMS and contact theft, microphone and camera access, APK installation, notification suppression, and interference with removal.
Android mobile trojan primarily used for on-device fraud via overlay attacks against online-banking users. It also has RAT capabilities through abuse of Android accessibility services to gather sensitive information and can uninstall the downloader app to reduce forensic footprint.
Android banking trojan used in TOAD/vishing campaigns against Italian banking users. It is delivered via a downloader posing as a security app/update, steals banking access through phishing-assisted fraud, provides remote-access capabilities via abused AccessibilityService, can overlay the screen to hide attacker actions, install/uninstall apps, send SMS, dial numbers, capture screenshots, and dynamically build fake input forms to harvest additional victim data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.