FvncBot Targets Android Users, Exploiting Accessibility Services for Attacks
ID: a42bb4b8-0313-5292-9f16-4a547823eb29
STIX ID: report--a42bb4b8-0313-5292-9f16-4a547823eb29
Feed Name: GBHackers
## Executive summary FvncBot is a newly observed Android banking trojan disguised as an mBank security app that leverages Accessibility Services to perform credential theft (keylogging, web‑inject overlays), remote UI inspection (HVNC/text‑mode UI tree), and H.264 screen streaming; it uses unencrypted HTTP/JSON for exfiltration and FCM plus an embedded Fast Reverse Proxy WebSocket for real‑time control. The campaign is currently focused on Polish users (call_pl build), the malware is obfuscated with APK0day, and observable indicators include the package name com.fvnc.app and C2 traffic to naleymilva.it.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
