Copybara
Copybara is an Android banking remote-access trojan active since the second half of 2021, primarily targeting customers of Italian financial institutions.
Profile source: Mallory opens in a new tabCopybara
Family profile
Copybara is an Android banking remote-access trojan active since the second half of 2021, primarily targeting customers of Italian financial institutions. It is used for on-device fraud and abuses Android Accessibility Services to let operators remotely interact with infected devices, including opening applications, performing taps and swipes, entering text, scrolling, blocking or uninstalling applications, and installing further applications. It supports screenshot-based screen streaming, screen capture, overlays that conceal fraudulent activity, and remote factory reset. Copybara uses institution-specific overlays and dynamically generated forms to collect personally identifiable information, and can use Accessibility event logging for broad keylogging. Companion functionality can monitor SMS messages to capture banking two-factor authentication codes. Campaigns commonly combine bank-themed phishing pages with SMS phishing and telephone-oriented attack delivery: victims are called by criminals impersonating bank support personnel and persuaded to sideload a purported security application and grant Accessibility permissions. Copybara has sometimes been incorrectly grouped with BRATA, but is distinct from the original BRATA family.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Post Exploitation
MITRE ATT&CK
Copybara in ATT&CK
26 distinct techniquesReporting
Research mentioning Copybara
TOAD attacks: Vishing combined with Android banking malware now targeting Italian banks
ThreatFabric reported that malware long grouped under the BRATA name is better understood as three separate Android banking malware families: the original BRATA, AmexTroll, and Copybara. The firm said AmexTroll and Copybara were active in parallel from late 2021 into 2022, share some development traits such as use of Basic4Android (B4A), and both support on-device fraud through screen streaming, abuse of Android AccessibilityService, and remote factory reset. But the two families diverge in targeting and delivery: AmexTroll expanded from Italy to nearly 50 financial institutions in Great Britain and Australia, including distribution through a Google Play dropper, while Copybara stayed focused on Italian banks and relied heavily on SMiShing and telephone-oriented attack delivery (TOAD). Separate reporting tied Copybara and earlier BRATA activity to fraud operations that combine phishing pages, spoofed SMS messages, and follow-up phone calls to coach victims into installing malicious Android apps. In the Italian TOAD campaigns, phishing sites harvested account numbers, PINs, phone numbers, and other answers before operators called victims and pushed a fake security app that downloaded the malware payload. Once installed, the malware enabled remote actions including opening apps, clicking, swiping, entering text, sending SMS, capturing screenshots, overlaying screens, intercepting one-time passwords, and validating stolen credentials for fraudulent banking transactions; newer Copybara samples could also generate fake forms on-device to collect more data. Researchers said the campaigns reflect a broader shift in mobile banking malware toward real-time, on-device fraud.