Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected. This malware is crafted to intercept sensitive financial data by capturing keystrokes, recording screens, and injecting fraudulent login interfaces into banking…

On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected. This malware is crafted to intercept sensitive financial data by capturing keystrokes, recording screens, and injecting fraudulent login interfaces into banking applications.

The malware proliferates through a counterfeit application masquerading as a security utility for mBank, a prominent Polish financial institution.

The deceptive application, titled "Klucz bezpieczeństwa mBank" (Security Key mBank), functions as a loader. Upon installation and activation, it covertly downloads and installs the primary FvncBot malware.

To conceal its operations, the malware employs the apk0day obfuscation service, complicating detection by security systems.

On Tue, Nov 25, 2025, a new Android banking malware identified as FvncBot was detected.
Mark Jensen · Thehackingpost

FvncBot distinguishes itself from prior banking malware by utilizing entirely new code instead of repurposing elements from threats like Ermac or Hook. The malware is equipped with sophisticated features aimed at victim exploitation:

Keylogging: Utilizes Android Accessibility Services to record every keystroke, including passwords, PINs, and OTPs, logging up to 1,000 events before transmitting via HTTP or WebSocket. Web-Inject Attacks: Projects deceptive overlay windows on legitimate banking applications to deceive users into divulging credentials. Phishing pages are received from a command server. Screen Streaming: Employs H.264 video compression to stream the device's screen in real-time, facilitating continuous monitoring with minimal bandwidth usage. HVNC (Hidden VNC): Allows remote device control by generating JSON UI element representations, enabling attackers to navigate, swipe, click, and input data remotely. Remote Command Execution: Establishes near-real-time bidirectional communication with command servers using WebSocket and Firebase Cloud Messaging (FCM). Device Manipulation: Capable of locking the device, muting audio, displaying black overlays, launching applications, and entering arbitrary data in text fields. Code Obfuscation: Obfuscation is achieved through the apk0day crypting service operated by the GoldenCrypt actor, aiming to evade detection and security analysis.

Attackers can manipulate devices to perform actions such as swiping, clicking, and entering text, potentially depleting bank accounts while the device appears locked or inactive.

Advertisement

The discovery of FvncBot by Intel471 emphasizes the necessity for users to download applications exclusively from official sources, like the Google Play Store. Users should remain vigilant against "security updates" or banking applications sourced from third-party websites or distributed through direct messaging, as these are common vectors for malware dissemination.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories