logo

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

ID: 18ec8d79-9ac1-5937-967d-c4e7a0dbb3b6

STIX ID: report--18ec8d79-9ac1-5937-967d-c4e7a0dbb3b6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

FvncBot is a newly observed, highly capable Android banking trojan distributed via a fake 'Klucz bezpieczeństwa mBank' app that acts as a loader; it abuses Android Accessibility Services to capture keystrokes and OTPs, deploys phishing overlays, streams the device screen, and provides hidden VNC-style remote control, while using apk0day obfuscation and WebSocket/FCM channels for command and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.