FvncBot Malware Leverages Android Accessibility Features To Attack Users

A new malware variant, FvncBot, has been discovered targeting Android users, specifically mobile banking customers in Poland.

This malware is distributed through a seemingly legitimate app called “Klucz bezpieczeństwa Mbank” (Eng. Security Key Mbank), which masquerades as a banking security tool. Upon installation, the app acts as a loader, silently deploying the FvncBot payload.

The application uses the APK0day crypting service to obfuscate both the loader and the payload code, making it difficult for security measures to detect.

Once installed, the app prompts users to install an additional component for “security” purposes, which, when activated, executes the malicious payload.

The loader is designed to bypass accessibility restrictions on newer Android versions (13 or higher) by leveraging a session-based package installer.

The bot communicates with its command-and-control (C2) server to send log events, tracking the bot’s current status and functionality.

Exploitation of Accessibility Services

Once the FvncBot payload is executed, it prompts the user to enable accessibility services, claiming they are needed for optimal operation.

If granted, the malware gains elevated privileges, allowing it to run in the background unnoticed while silently sending data to the C2 server.

The image depicts a screenshot of the payload installation process captured Nov. 27, 2025. (Source: intel471)
The image depicts a screenshot of the payload installation process captured Nov. 27, 2025. (Source: intel471)

The bot operates through HTTP and Firebase Cloud Messaging (FCM) to receive commands and transmit data.

For instance, commands can enable WebSocket connections, facilitating near-real-time, bidirectional communication between the infected device and attackers. This is essential for tasks like screen streaming or remote device control.

The image depicts a screenshot of a function used to install a malware payload captured Nov. 27, 2025. (Source: intel471)
The image depicts a screenshot of a function used to install a malware payload captured Nov. 27, 2025. (Source: intel471)

Key features of FvncBot include:

  • Keylogging: Using accessibility services, the malware monitors and logs keystrokes, capturing sensitive data like passwords and one-time passwords (OTPs).
  • Web-inject Attacks: Malware can overlay phishing lures onto legitimate applications, capturing user credentials once they are entered.
  • Screen Streaming: Upon command, the bot can stream the infected device’s screen in H.264 format, using less bandwidth than JPEG.
    • Remote Control: The bot can remotely control the infected device by sending swipe, click, or scroll commands over a WebSocket connection, allowing attackers to manipulate the device without the user’s knowledge.

Exfiltration and Remote Control

According to intel471, the malware exfiltrates sensitive data, including device information and user credentials, in JSON format. It can send this data using HTTP POST requests to the C2 server, without encryption, making it vulnerable to interception.

Once registered with the server, the bot can receive updated lists of targeted applications for phishing or keylogging. These applications can be dynamically adjusted via commands sent from the C2 server.

Additionally, FvncBot implements a feature often referred to as HVNC (Hidden VNC), enabling the attackers to inspect the device’s UI layout without taking screenshots.

The image depicts a screenshot of a process enabling the accessibility service of the payload application captured Nov. 27, 2025 (Source: intel471)
The image depicts a screenshot of a process enabling the accessibility service of the payload application captured Nov. 27, 2025 (Source: intel471)

This allows them to reconstruct the device’s screen remotely, even when applications have protections such as the FLAG_SECURE setting, which normally prevents screenshots.

FvncBot highlights the increasing sophistication of Android banking malware, which leverages accessibility services to enable advanced features such as keylogging, screen streaming, and remote control.

While this particular malware targets Polish users, its design allows for easy modification, meaning future versions could target other regions or impersonate other institutions.

The use of web injects enables the malware to capture sensitive data, such as OTPs and payment card information.

This makes detection difficult, as the injected forms often appear legitimate to the victim. Users must be cautious about downloading applications from unofficial sources and ensure their devices’ security settings are properly configured to avoid falling victim to such attacks.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories