Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads

An Android banking trojan named FvncBot has been identified as a sophisticated threat to mobile banking users in Poland. Initially discovered by Intel 471 on Tue, Nov 25, 2025, this malware masquerades as a security application from mBank, a major Polish…

An Android banking trojan named FvncBot has been identified as a sophisticated threat to mobile banking users in Poland. Initially discovered by Intel 471 on Tue, Nov 25, 2025, this malware masquerades as a security application from mBank, a major Polish banking institution.

Novel Malware with Advanced Capabilities

FvncBot represents a new strain of Android malware, distinct from previous threats as it does not rely on leaked source code from other banking trojans. Named after its application package identifier "com.fvnc.app," the malware shows significant technical sophistication.

The infection process involves a two-stage approach. A loader application prompts users to install a seemingly legitimate "Play component" for security purposes. Once activated, the loader deploys the FvncBot payload, stored unencrypted in the application's assets.

The malware uses Android's accessibility services to perform keylogging, capturing sensitive data such as passwords and one-time password codes. Captured data is stored in a buffer that holds up to 1,000 items before being transmitted via HTTP requests.

An Android banking trojan named FvncBot has been identified as a sophisticated threat to mobile banking users in Poland.
Iris Emerson · Thehackingpost

FvncBot executes web-injection attacks by displaying phishing pages over legitimate banking applications. These pages, loaded in WebView components, use custom JavaScript interfaces to capture credentials. The list of targeted applications and phishing URLs is retrieved from a command-and-control server and stored locally on infected devices.

The malware allows attackers to remotely control infected devices through WebSocket connections, enabling actions such as launching applications, entering data, and manipulating the clipboard. To conceal fraudulent activities, it can lock devices, mute audio, and display black overlays.

Advertisement

Screen streaming is implemented using the MediaProjection API with H.264 video encoding for efficient bandwidth use. Additionally, FvncBot features a "text mode" that reconstructs device screens by analyzing UI elements through accessibility services, bypassing screenshot prevention measures.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories