A new Android banking trojan has emerged, combining traditional overlay attacks with a hidden Virtual Network Computing (VNC) server to achieve full remote control of infected devices.

This malware was first detected in late September 2025 and is distributed via SMS phishing, which trick victims into installing a fake “security” app.
Once it receives the necessary permissions, the trojan encrypts its payload, avoiding detection of static files, and launches a VNC server in the background that remains invisible in the user's device launcher.
How does the Android banking trojan work?
Cleafy analysts discovered the malware after noticing unusual network traffic from mobile phone users of several European banks . After installation, the trojan immediately requests Accessibility and Device Administrator permissions under the guise of optimizing device performance.
See also: Malicious users take over MS-SQL Server and deploy XiebroC2
These permissions allow it to intercept touch input, record screen information , and silently create fake overlays to display pages for legitimate banking applications.
At the same time, the VNC module initializes a hidden framebuffer, allowing malicious users to view and manipulate the device in real time.
VNC server
While overlay-based trojans have been around for years, the integration of a headless VNC server into this new form is a significant change. Instead of relying solely on screen overlays, attackers can now navigate the device interface as if they were holding it in their hands—opening applications, entering one-time passwords, and installing additional payloads.
Early cases show that victims remain unsuspecting of the remote session, as the Android banking trojan suppresses all visual indicators and records user interactions to merge with legitimate activity.

Once installed, the trojan uses multiple persistence. It registers a broadcast receiver for BOOT_COMPLETED to restart the VNC service upon device reboot and connects to AccessibilityService to monitor screen state changes.
See also: Datzbro: New Android trojan scams elderly people
The malware also disables Google Play Protect by secretly exploiting system APIs, preventing updates or scans that could disrupt its operation.
These layers of defense ensure that remote access remains active until it is manually removed—a task complicated by the trojan's ability to hide its icon and camouflage itself with system-level names.
Android banking trojan: Infection chain
The infection chain starts with a deceptive SMS message containing a download link for a trojanized APK named “BankGuard.apk“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
When the user installs this package, they are asked to enable two critical permissions: AccessibilityService and Device Administrator. Once granted, the malware programmatically registers its AccessibilityService.
With these connections in place, the trojan silently starts the VNC server. This headless server records framebuffer data and listens commands remote control.
See also: New Spear-Phishing Attack Distributes DarkCloud Malware
Attackers connect using off-the-shelf VNC clients, gaining unrestricted interactive control over the victim's device. Through this mechanism, the trojan bypasses traditional overlay detection by avoiding UI injection altogether and relying on genuine touch emulation via remote commands.

Protection from banking trojan
- Installing antivirus software is essential for protecting your device. These software can identify and remove malware before it can cause damage.
- It's important to keep your operating system and applications up to date. Updates often include security fixes that can protect your device from malware.
- Avoid installing apps from third-party sources. These apps have not undergone the same security checks as those in official stores.
- Pay attention to the permissions apps ask for. If an app asks for access to personal information that doesn't seem necessary, it may be best not to install it.
- Be wary of phishing messages that may try to trick you into downloading malware. These messages may appear to come from legitimate sources, but they often contain links or attachments that can install malware on your device.
- Use strong passwords and implement multi-factor authentication (MFA) where possible.
- Finally, it's important to regularly back up your data. This can help restore your information if your device is infected with malware.
