New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads
On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected. This malware is crafted to intercept sensitive financial data by capturing keystrokes, recording screens, and injecting fraudulent login interfaces into banking…
On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected. This malware is crafted to intercept sensitive financial data by capturing keystrokes, recording screens, and injecting fraudulent login interfaces into banking applications.
The malware proliferates through a counterfeit application masquerading as a security utility for mBank, a prominent Polish financial institution.
The deceptive application, titled "Klucz bezpieczeństwa mBank" (Security Key mBank), functions as a loader. Upon installation and activation, it covertly downloads and installs the primary FvncBot malware.
To conceal its operations, the malware employs the apk0day obfuscation service, complicating detection by security systems.
On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected.
FvncBot distinguishes itself from prior banking malware by utilizing entirely new code instead of repurposing elements from threats like Ermac or Hook. The malware is equipped with sophisticated features aimed at victim exploitation:
Keylogging: Utilizes Android Accessibility Services to record every keystroke, including passwords, PINs, and OTPs, logging up to 1,000 events before transmitting via HTTP or WebSocket. Web-Inject Attacks: Projects deceptive overlay windows on legitimate banking applications to deceive users into divulging credentials. Phishing pages are received from a command server. Screen Streaming: Employs H.264 video compression to stream the device's screen in real-time, facilitating continuous monitoring with minimal bandwidth usage. HVNC (Hidden VNC): Allows remote device control by generating JSON UI element representations, enabling attackers to navigate, swipe, click, and input data remotely. Remote Command Execution: Establishes near-real-time bidirectional communication with command servers using WebSocket and Firebase Cloud Messaging (FCM). Device Manipulation: Capable of locking the device, muting audio, displaying black overlays, launching applications, and entering arbitrary data in text fields. Code Obfuscation: Obfuscation is achieved through the apk0day crypting service operated by the GoldenCrypt actor, aiming to evade detection and security analysis.
Attackers can manipulate devices to perform actions such as swiping, clicking, and entering text, potentially depleting bank accounts while the device appears locked or inactive.
The discovery of FvncBot by Intel471 emphasizes the necessity for users to download applications exclusively from official sources, like the Google Play Store. Users should remain vigilant against "security updates" or banking applications sourced from third-party websites or distributed through direct messaging, as these are common vectors for malware dissemination.
Based on reporting by Cyber Security News.
