FvncBot is a newly identified Android banking malware that steals financial data by logging keystrokes, streaming screens, and injecting fake banking pages. Analysts first spotted it on November 25, 2025 and traced it to a fake mBank security tool that installs the payload in the background. The malware hides behind heavy obfuscation and runs complex features that give attackers full control of a victim’s device. Security researchers note that its codebase is original, which signals active development rather than recycled malware.
Relevant Source (Intel471): New FvncBot Android Banking Trojan Targets Poland
Intel471 details how FvncBot impersonates an mBank security app, logs credentials, and enables remote control of infected Android devices for banking fraud.
Quick Facts
- Spread through a fake app impersonating an mBank security tool.
- Logs keystrokes including passwords and one-time codes.
- Injects banking overlays to steal credentials.
- Streams screens in real time for full monitoring.
- Lets attackers remotely control the phone with hidden VNC functions.
- Uses apk0day obfuscation to evade detection.
How FvncBot Hijacks Devices
FvncBot is an advanced Android malware designed to capture financial data and gain remote control of infected devices. Attackers use a fake “Security Key mBank” app as a loader that installs the malware once opened. The payload abuses Android’s Accessibility Services to intercept keystrokes, display phishing overlays, and monitor activity in real time. The malware communicates continuously with command servers to receive instructions for screen streaming, remote actions, and device manipulation.
- Captures up to 1,000 keystrokes before exfiltrating the data.
- Streams the screen using compressed video for live monitoring.
- Creates fake banking login pages controlled remotely.
FvncBot operates quietly while performing actions that leave victims unaware that their accounts are being accessed in the background.
Relevant Source (GBHackers On Security): FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads
Researchers describe how FvncBot abuses Android accessibility services for keylogging, screen recording, and overlay attacks to remotely control infected banking devices.
Why FvncBot Is Dangerous
FvncBot poses a serious risk because it blends phishing, keylogging, and remote control into a single tool that sidesteps most consumer defenses. Attackers can navigate banking apps, enter credentials, and execute transactions while victims see a black screen or locked phone. Its original codebase and strong obfuscation make it harder for antivirus tools to catch early. Intel471 reports show that the threat actors behind FvncBot designed it for efficiency and stealth rather than crude credential theft.
- High risk for unauthorized bank transfers.
- Harder for security scanners to detect due to obfuscation.
- Delivers overlays that look identical to real banking interfaces.
- Allows attackers to automate account takeover steps.
- Expands the trend of financial malware using legitimate Android permissions.
FvncBot raises the urgency for users to be careful about where they download banking apps and updates.
Relevant Source (Malwarebytes): New Android malware lets criminals control your phone and drain your bank account
Malwarebytes describes Albiriox, an Android banking trojan that uses overlays, live remote control, and black-screen tricks to quietly drain bank accounts, illustrating the same blended risks of keylogging, overlays, and device takeover seen with FvncBot.
Protecting Against FvncBot Malware
Staying safe from FvncBot comes down to controlling where apps come from and avoiding side-loaded installers that claim to be security tools. Real banks do not send APKs by text or host updates on third-party sites. FvncBot depends on users installing the fake loader, so strong download discipline stops the threat before it starts.
Steps to follow:
- Install apps only from Google Play.
- Ignore banking “security keys” or updates sent by message or email.
- Check app publishers before installing.
- Remove any banking app that asks for unusual Accessibility permissions.
- Run a trusted mobile security scanner if something feels off.
Good habits with downloads block nearly every path FvncBot uses to infect devices.
Relevant Source (Cryptomathic): Mobile Banking App Security: Malware Protection Insights
Cryptomathic outlines how users should only install apps from official stores, avoid links in SMS, and keep built-in Android security enabled to reduce banking malware risk.
Evolving Android Banking Malware Threat
Android financial malware continues to evolve because attackers know how often people perform banking tasks on their phones. FvncBot stands out because it combines live screen streaming, HVNC control, and phishing overlays in one package that gives criminals far-reaching access. The malware does not rely on repurposed code, which means the developers will likely iterate and improve its capabilities.
Security teams stress that side-loaded banking tools remain one of the most common infection vectors. FvncBot’s use of a fake mBank security update shows that criminals will continue to lean on impersonation because it works on unsuspecting users. The threat will grow if more groups adopt similar techniques.
Relevant Source (Cleafy): Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets
Cleafy details how the Albiriox Android malware family uses remote control, screen manipulation, overlays, and sideloaded droppers, showing how modern banking trojans are rapidly evolving in the same direction as FvncBot.
Stay Safe From Android Malware
FvncBot is a reminder that Android malware often hides behind apps posing as updates, tools, or account verification helpers. Careful control over what gets installed keeps your financial data out of reach. Users who stick to official sources and avoid random APKs significantly reduce the risk of losing money to remote-access banking malware.
Relevant Source (Microsoft Security): Social engineering attacks lure Indian users to install Android banking trojans
Microsoft details how Android banking trojans spread through fake app updates and messages, and urges users to install apps only from official stores and avoid unknown APKs.
FAQ
What is FvncBot?
A newly discovered Android malware that logs keystrokes, injects phishing overlays, streams screens, and enables remote control.
How does it spread?
Through a fake mBank security tool called “Klucz bezpieczeństwa mBank” distributed outside Google Play.
Why is it dangerous?
It gives attackers full navigation and control of a device while hiding activity with black screens or lock screens.
Can antivirus apps detect it?
Detection is difficult because the malware uses heavy obfuscation, but reputable scanners may flag related behaviors.
How do I avoid infection?
Download apps only from Google Play, avoid APKs shared by message, and deny suspicious Accessibility permissions.

JENI Systems And Device Security Support
JENI helps users keep their devices stable and less vulnerable to the system weaknesses that malware often targets. Routine cleanup, cache repair, and system optimization lower the chances of hidden processes lingering unnoticed. Strong diagnostic tools give users a clearer view of system behavior so suspicious activity stands out earlier.
How JENI Strengthens Device Health:
- Repairs corrupted system components that malware often abuses.
- Clears junk data to reduce background activity that hides threats.
- Improves stability so unusual behavior becomes easier to detect.
JENI does not replace antivirus tools, yet it supports a healthier device ecosystem that makes infections easier to spot. Clean systems respond faster, reveal anomalies quicker, and minimize the clutter that attackers rely on when hiding malicious actions. Users benefit from predictable performance that makes sudden changes more noticeable. A stable device reduces the attack surface that threats like FvncBot attempt to exploit.
