New FvncBot Attacking Android Users by Exploiting Accessibility Services
ID: ce8a068a-87b2-5b9d-add1-9a360f1ba2aa
STIX ID: report--ce8a068a-87b2-5b9d-add1-9a360f1ba2aa
Feed Name: cybersecurityNews.com
Threat Score
A newly identified Android banking trojan called FvncBot, observed on 2025-11-25 targeting Polish banking customers, impersonates an mBank security app and tricks users into installing a secondary "Play" component to bypass protections. It requests Accessibility privileges to log keystrokes and capture screens, uses WebSockets for real-time control, and provides hidden VNC-style remote access to enable fraudulent transfers and persistent theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
