logo

New FvncBot Attacking Android Users by Exploiting Accessibility Services

ID: ce8a068a-87b2-5b9d-add1-9a360f1ba2aa

STIX ID: report--ce8a068a-87b2-5b9d-add1-9a360f1ba2aa

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-06

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A newly identified Android banking trojan called FvncBot, observed on 2025-11-25 targeting Polish banking customers, impersonates an mBank security app and tricks users into installing a secondary "Play" component to bypass protections. It requests Accessibility privileges to log keystrokes and capture screens, uses WebSockets for real-time control, and provides hidden VNC-style remote access to enable fraudulent transfers and persistent theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.