HomeSecurityFvncBot: New Android banking malware steals data

FvncBot: New Android banking malware steals data

A new, highly advanced Android banking malware, dubbed FvncBot, was first detected on November 25, 2025, sparking concerns among cybersecurity experts. The malware is designed to steal financial data, monitor the victim's device in real time, and allow attackers complete remote control.

FvncBot Android banking malware

How it's distributed: A fake "secure" mBank app

The attacks are launched by a fake application that appears to be a security tool from the popular Polish bank mBank. The application is titled “Klucz bezpieczeństwa mBank” (mBank Security Key) and acts as a loader . Although it looks legitimate, once the user opens it, it silently downloads the real FvncBot payload.

To make detection systems difficult, the malware uses the apk0day, known for its ability to encrypt malicious code in a way that makes static and dynamic analysis extremely difficult.

See also: How to protect your smartphone from spyware

A new generation of malware

Unlike many current threats that rely on the same reused code ecosystem — such as the well-known banking trojans Ermac and Hook— FvncBot appears to have been written entirely from scratch. The originality of the code suggests that this is a new, highly sophisticated cybercrime group.

Its capabilities rank it among the most complete mobile malware frameworks of recent years.

Android adware

Technical Capabilities: How FvncBot Fully Takes Over the Device

Keylogging via Accessibility Services

FvncBot exploits Android's Accessibility Services, which allows it to record every keystroke, including PINs, passwords, OTPs , and other sensitive data. It can store up to 1,000 events before exporting them to its servers via HTTP or WebSocket.

See also: ClayRat: Android spyware steals messages and photos

Web-injects and phishing in banking applications

The web-inject feature allows the malware to display fake login windows on top of legitimate banking applications. This way, victims think they are entering credentials into the real application, but in reality they are sending them to the attackers.

Phishing pages are downloaded dynamically from the command-and-control server, making them highly customizable.

Real-time screen streaming

FvncBot supports screen streaming real-time , using H.264 compression for lower bandwidth consumption. Attackers can see exactly what the user is doing, without the victim having any clue.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

HVNC: The complete remote control

The most dangerous mechanism of FvncBot is the HVNC (Hidden VNC).
Unlike classic VNC, HVNC creates an invisible user interface environment, allowing attackers to perform actions in the background while the victim's screen remains locked or blacked out.

They can scroll, tap, enter text, open applications and—in the worst case—make money transfers without the user realizing it.

See also: Phishing or malware: Which is the bigger threat to corporate users?

Remote commands and device control

FvncBot supports real-time communication via WebSocket and Firebase Cloud Messaging (FCM), allowing attackers to execute commands such as:

  • Device lock
  • Mute sounds
  • Launch specific applications
  • Entering data into text fields
  • Show a black screen to hide activity

The use of the apk0day encryption service makes it extremely difficult to detect the malware.

FvncBot: New Android banking malware steals data

How can users be protected?

Only official app sources – never outside the Play Store

Intel471 's discovery of FvncBot serves as a reminder that users should only install apps from official sources, such as the Google Play Store . Fake security updates and banking apps distributed via third-party websites or private messages are currently one of the most common entry points for such threats.

Increased vigilance is necessary

With new-generation Android banking malware like FvncBot, simple caution is not enough. Banking institutions are urged to strengthen their detection systems, while users should be extremely cautious of any “notification” that invites them to install applications outside of official channels.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS