
Your phone rings — a calm, professional voice claims to be your bank's security team. There's suspicious activity on your account, they say, and you need to install a special verification app right away. It is not your bank. And that "security app" may already be handing a criminal complete remote control of your phone.
Security researchers at d3 Lab documented exactly this pattern in a campaign impersonating the digital bank N26, reported in the first days of August 2026. The attack begins with repeated calls — sometimes an automated recorded message, sometimes a live person — both claiming to represent the bank's support team. The caller deliberately builds urgency around account security, then steers the victim away from the bank's official, trusted channels toward a phone number or link the attacker controls directly.
An urgent call about suspicious activity. The caller sounds professional and patient — just like a real bank rep.
The victim is convinced to install Copybara — an Android remote access trojan built specifically to abuse Android's Accessibility Services feature.
The malware installs under a name resembling an official certificate tool, then later poses as a "Battery Cleaner" utility — complete with fake battery, memory, and temperature readouts, all hard-coded and entirely fictional.
With Accessibility permissions granted, the attacker can silently operate the phone, read anything on screen, and interact with any app — including banking apps — entirely in the background.
One-time passcodes, banking balances, and any text visible on screen are captured in real time.
SMS messages, including verification codes, are captured and forwarded to the attacker.
Saved contacts are silently collected from the device.
The malware can attempt to move money directly inside your banking app while a fake loading screen keeps you distracted.
This N26 campaign is not an isolated invention. Related Android banking trojans in this same family have previously targeted mobile banking users across Italy and Spain, impersonating dozens of different financial brands, and separate but similar malware families have specifically hijacked calls a victim makes to their own bank's real support line, redirecting the call to the attacker instead while displaying a fake screen that looks identical to a genuine call in progress.
Across every version of this scheme, the underlying pattern is the same: a phone call creating urgency, followed by an instruction to install something or move to an untrusted channel outside your bank's own official app or website.
Your bank will never ask you to install a security or verification app mid-call. Treat this as a certain scam, no matter how convincing the caller sounds.
If a call about account security arrives unexpectedly, hang up and call your bank using the number on your card or their official website — never a number the caller gives you.
Install banking apps only from your bank's verified app store listing, confirmed against the developer name on your bank's own website. Never use a link or file sent during a call.
Periodically review which apps hold Accessibility permissions (Settings → Accessibility or Installed Services) and remove anything you don't recognize or actively use.
Disconnect from Wi-Fi and mobile data immediately, contact your bank through a verified channel to freeze your account if needed, and have the device professionally checked before using any financial app again.
Legitimate bank security processes never require you to install a new app during an unexpected call. Treat that combination — an urgent unsolicited call plus an instruction to install something — as an automatic red flag. It protects you against this entire category of fraud, regardless of which bank or brand a future version of this scam impersonates.
Traditional antivirus tools catch malware that reaches out to malicious servers, exploits vulnerabilities, or modifies system files. Accessibility abuse is different — it uses a genuine, developer-approved Android feature, just for a purpose its creators never intended.
Security researchers increasingly focus on behavioural red flags: an app requesting Accessibility permissions with no clear disability-support purpose, or a banking-adjacent app arriving via a phone call rather than an official app store.
For everyday users, the most reliable protection isn't a security app — it's the simple habit of never installing something because an unexpected caller told you to, no matter how urgent or official they sound.
Do not wait. Disconnect your device from the internet immediately to cut off the malware's operators, then contact your bank on a verified number to freeze your accounts. Have the device examined by a qualified professional before reconnecting it to any network or logging into any financial account.
No real Australian bank will ever ring you out of the blue and ask you to install something. Ever. Full stop.
Don't trust any number the caller gives you. Hang up, flip your card over, and ring that number yourself.
Go to Settings → Accessibility → Installed Services. If you see an app you don't recognise, remove its access straight away.
Cutting off the internet connection is the fastest way to stop a malicious app from sending your data to criminals while you work out what to do next.
A quick yarn with a parent or grandparent about this scam today could save them from a devastating financial loss tomorrow.
Not sure what some of these tech terms mean? No worries — here's a quick guide.
A type of malicious app that lets a criminal control your phone or computer from far away — like someone else grabbing your steering wheel while you're driving.
A built-in Android feature designed to help people with disabilities use their phones. It lets apps read your screen and tap things on your behalf. Legitimate uses include screen readers for the visually impaired — but crooks can abuse it to silently control your phone.
Short for "malicious software." Any app or program designed to harm you, steal your information, or give someone else control of your device without your knowledge.
The specific name researchers gave to the malware used in this scam campaign. It disguises itself as a legitimate-looking app while secretly giving criminals access to your phone.
A short code your bank sends to your phone via SMS to verify it's really you logging in or making a transaction. This malware can read and steal these codes before you even see them.
A setting on your phone that cuts off all wireless connections — Wi-Fi, mobile data, and Bluetooth. Switching this on stops a malicious app from sending your information to criminals while you sort out the problem.
A scam carried out over the phone where a criminal pretends to be someone trustworthy — like your bank — to trick you into handing over money or access to your accounts.
The page for an app on the Google Play Store or Apple App Store. Always download banking apps from here — never from a link sent in a text, email, or phone call.
Your Bank Never Called That Number