Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

Posted on December 6, 2025December 6, 2025 By CWS

A harmful new Android banking malware named FvncBot was first noticed on November 25, 2025. This malicious device is designed to steal delicate monetary data by logging keystrokes, recording screens, and injecting pretend login pages into banking apps.

The malware initially spreads by way of a pretend software disguised as a safety device for mBank, a preferred Polish financial institution.

The accessibility service of the payload software

The app, named “Klucz bezpieczeństwa mBank” (Safety Key mBank), acts as a “loader”. As soon as a person installs and opens this pretend app, it secretly downloads and installs the first FvncBot payload.

To cover its exercise, the malware makes use of a identified obfuscation service known as apk0day, making it more durable for safety methods to detect.

Bot debug messages

Researchers say FvncBot is totally different from different banking malware. As an alternative of reusing code from older threats like Ermac or Hook, its code appears to be like fully new.

FvncBot is very superior and consists of a number of highly effective options to defraud victims:

FeatureDescriptionKeyloggingAbuses Android Accessibility Companies to seize each keystroke, together with passwords, PINs, and OTPs. Logs as much as 1,000 occasions earlier than exfiltrating by way of HTTP or WebSocket.Internet-Inject AttacksDisplays pretend overlay home windows on reliable banking apps to trick customers into coming into credentials. Phishing pages obtained from command server.Display screen StreamingStreams machine display in real-time utilizing H.264 video compression for environment friendly bandwidth utilization and steady monitoring.HVNC (Hidden VNC)Allows distant machine management by creating JSON UI component representations. Permits attackers to navigate, swipe, click on, and enter information.Distant Command ExecutionUses WebSocket connection and Firebase Cloud Messaging (FCM) for near-real-time bidirectional communication with command servers.Machine ManipulationCapable of locking machine, muting audio, displaying black overlays, launching purposes, and coming into arbitrary information into textual content fields.Code ObfuscationObfuscated utilizing apk0day crypting service operated by GoldenCrypt actor to evade detection and safety evaluation.

They’ll swipe, click on, and even enter textual content to empty financial institution accounts whereas the telephone seems locked or blacked out.

The Intel471 discovery of FvncBot underscores the significance of downloading apps solely from official sources, such because the Google Play Retailer.

Log information collected from an overlay

Customers ought to be cautious of “safety updates” or banking apps discovered on third-party web sites or despatched by way of direct messages, as these are widespread traps used to ship such a malware.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Android, Attacking, Banking, FvncBot, Inject, Keystrokes, Log, Malicious, Payloads, Users

Post navigation

Previous Post: Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
Next Post: Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Related Posts

AI-Powered Apex Enhances App Security by Finding Vulnerabilities AI-Powered Apex Enhances App Security by Finding Vulnerabilities Cyber Security News
Linux Legitimate System Behaviours Weaponized to Harvest Secrets from Shared Environments Linux Legitimate System Behaviours Weaponized to Harvest Secrets from Shared Environments Cyber Security News
Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Cyber Security News
Oblivion RAT: New Android Threat with Hidden Control Oblivion RAT: New Android Threat with Hidden Control Cyber Security News
OneLogin AD Connector Vulnerabilities Exposes Authentication Credentials OneLogin AD Connector Vulnerabilities Exposes Authentication Credentials Cyber Security News
PoC Published For Fortinet 0-Day Vulnerability That Being Exploited in the Wild PoC Published For Fortinet 0-Day Vulnerability That Being Exploited in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark