This page is the attacker. It is on a different registrable domain from the target site
and it never receives the target's cookie in JavaScript: that cookie is HttpOnly,
Secure, SameSite=Strict and host-only.
bank.teiubescdalghezamea.apphttps://bank.teiubescdalghezamea.app/export.bin, a download-triggering URL on the target site. In Arc
that alone produces an authenticated HEAD plus an authenticated GET and
writes the victim's private response body into /sdcard/Download/. Check
the raw log.