FvncBot is an Android banking trojan targeting mobile banking users in Poland. It is commonly disguised as a banking-security or bank-branded protection application, including lures themed around Polish financial institutions such as mBank and SGB, and uses staged installation flows to persuade victims to install additional components and grant high-risk permissions. The malware has been described as an original codebase rather than a derivative of leaked Android banking trojan source code.
FvncBot relies heavily on abuse of Android Accessibility Services to obtain broad visibility and control over the device. Once enabled, it can capture keystrokes and text changes, inspect the active user interface hierarchy, monitor user interactions, perform gestures, invoke global navigation actions, and support remote operator control. Reported functionality includes hidden VNC or HVNC-style remote interaction, screen capture and live screen streaming, overlay and web-injection style content presentation, and command execution through persistent backend communications including WebSocket and Firebase Cloud Messaging-based tasking. Multi-stage samples have also used dynamic code loading and concealed payload extraction to hinder analysis and modularize deployment.
Operationally, FvncBot is designed to facilitate account takeover and fraudulent banking transactions directly from the victim device, allowing operators to act within legitimate banking sessions and thereby reduce friction from conventional fraud controls. It also supports exfiltration of device telemetry, harvested input, and other event data. Observed campaigns have focused on Polish internet and banking users and have used fake update or fake security-app narratives to socially engineer installation and privilege enablement. FvncBot has also been linked in reporting to criminal malware-enablement ecosystems, including use of commercial crypting services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Ścieżka nakładek pozwala też na wstrzyknięcie spersonalizowanego JavaScript do zawartości WebView w celu zachowania widoczności pól wprowadzania danych
Użytkownik uruchamia aplikację wykorzystującą wizerunek SGB... tekst nakłaniający go do uruchomienia procesu instalacji za pomocą guzika Install Component | Głównym motywem socjotechnicznym obserwowanej kampanii jest właśnie opisany wyżej podział - widoczna fasada z logotypem i szatą graficzną banku ma na celu zwabienie użytkownika w pułapkę... Ofiara jest następnie nakłaniana do zezwolenia na uruchomienie funkcji ułatwień dostępu pod pretekstem uaktualnienia systemu
W następnym kroku ładowany jest instalator z /data/user/0/com.junk.knock/app_tell/tWyWeG.txt używając DexClassLoader ... A dynamiczna analiza próbki potwierdza dokładną ścieżkę wywołania: { "tag" : "DYNAMIC_CODE_LOADING" , "details" : { "loader" : "DexClassLoader"
“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies.
Poniższe ciągi jasno pokazują sposób zamaskowania drugiego etapu jako rzekomego komponentu systemowego: <string name="accessibility_service_notification_title"> System Update </string> <string name="app_name"> Android V.28.11 </string> <string name="service_notification_title"> System Component </string>
Ukryty zasób jest przekształcany za pomocą procesu podobnego do RC4 wprowadzanego przez sDjCM ... Analiza offline potwierdziła, że zastosowanie RC4 z kluczem sDjCM do pierwotnej wersji pliku qkcCg.jpg skutkuje uzyskaniem archwium ZIP zawierającego finalną wersję classes.dex
The installer checks the second-stage provider to see whether accessibility is already enabled: Cursor cursorQuery = getContentResolver().query(Uri.parse("content://" + INSTANCE.getPROVIDER_AUTHORITY()), null, null, null, null);
W następnym kroku ładowany jest instalator z /data/user/0/com.junk.knock/app_tell/tWyWeG.txt używając DexClassLoader ... A dynamiczna analiza próbki potwierdza dokładną ścieżkę wywołania: { "tag" : "DYNAMIC_CODE_LOADING" , "details" : { "loader" : "DexClassLoader"
Dane zawierają build ID, package name, wersję aplikacji, ID urządzenia, wersję systemu Android i model urządzenia
Usługa tworzy pełną reprezentację wyświetlanego ekranu w pliku JSON, zawierającą tekst, opis zawartości, identyfikatory widoków, granice na ekranie, role oraz elementy podrzędne
Moduł przechwytuje zmiany tekstu z edytowalnych pól i zapisuje zarówno pierwotne, jak i zedytowane wartości
The operator can instruct the implant to display URL, HTML, black-screen, or loading overlays.
Observed backend traffic: https://jeliornic.it.com/api/v1/tracking/events https://jeliornic.it.com/api/v1/devices/register https://jeliornic.it.com/api/v1/devices/device_bf43438cc5236391/events/batch
FCM wspiera też sesje websocketowe ... Metoda przyjmuje adres websocketu i klucz do API ... Klient websocketowy jest zbudowany na bazie OkHttp | Proces rejestracji urządzenia jest wskazany wprost w źródłach ... /api/v1/devices/register ... Do uwierzytelniania w komunikacji HTTP wykorzystano zarówno nagłówek X-API-Key jak i X-Device-ID
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a malware family reportedly affiliated with the GoldenCrypt crypting service provider.
Multi-stage Android malware used in campaigns impersonating Polish banks. It installs additional modules, abuses Accessibility Services, registers infected devices with attacker infrastructure, supports remote control via gestures and global actions, captures text and UI content, can display overlays/web content, and enables screen streaming and WebSocket-based operator sessions.
Named as one of 17 Android malware families detected in the wild over four months.
A multi-stage Android remote-control implant chain disguised as Polish banking/security apps. It installs a hidden second-stage app, abuses Accessibility Services for remote control, keylogging, UI-tree capture, overlays/web-injects, screen streaming, command polling, and backend registration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.