logo

New Copybara Malware Remotely Hijacks Your Android Device

ID: 5e46f188-4984-5e82-8a34-ae3717174df8

STIX ID: report--5e46f188-4984-5e82-8a34-ae3717174df8

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-08-23

Date Updated: 2026-04-19

Author: Kaaviya

...
...

Copybara is a persistent Android banking Trojan (active since 2021) that targets users—notably in Italy and Spain—by distributing fake apps and phishing pages that mimic banks and cryptocurrency exchanges. The November 2023 variant adopts MQTT for C2 communications and, once Accessibility Service is enabled, can keylog, record audio/video, intercept SMS, take screenshots, lock devices, steal credentials, download/install additional malicious apps, and exfiltrate data; the report includes phishing links, malicious APK names, and evidence of live C2-hosted phishing pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.