Last seven days
- First activity
- Sep 11, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
FvncBot is an Android banking trojan targeting mobile banking users in Poland.
Profile source: Mallory opens in a new tabFvncBot
FvncBot is an Android banking trojan targeting mobile banking users in Poland. It is commonly disguised as a banking-security or bank-branded protection application, including lures themed around Polish financial institutions such as mBank and SGB, and uses staged installation flows to persuade victims to install additional components and grant high-risk permissions. The malware has been described as an original codebase rather than a derivative of leaked Android banking trojan source code.
FvncBot relies heavily on abuse of Android Accessibility Services to obtain broad visibility and control over the device. Once enabled, it can capture keystrokes and text changes, inspect the active user interface hierarchy, monitor user interactions, perform gestures, invoke global navigation actions, and support remote operator control. Reported functionality includes hidden VNC or HVNC-style remote interaction, screen capture and live screen streaming, overlay and web-injection style content presentation, and command execution through persistent backend communications including WebSocket and Firebase Cloud Messaging-based tasking. Multi-stage samples have also used dynamic code loading and concealed payload extraction to hinder analysis and modularize deployment.
Operationally, FvncBot is designed to facilitate account takeover and fraudulent banking transactions directly from the victim device, allowing operators to act within legitimate banking sessions and thereby reduce friction from conventional fraud controls. It also supports exfiltration of device telemetry, harvested input, and other event data. Observed campaigns have focused on Polish internet and banking users and have used fake update or fake security-app narratives to socially engineer installation and privilege enablement. FvncBot has also been linked in reporting to criminal malware-enablement ecosystems, including use of commercial crypting services.
Samples
Reported operators
“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.