# FvncBot — financial-services

Published: 2026-03-30 · Severity: medium · Sectors: financial-services
Canonical: https://vorant.io/reports/22a45c29-95b0-48d6-97cc-187f9d9059e0/fvncbot-financial-services

> FvncBot campaign deploys multi-stage Android banking trojan via fake SGB bank apps, leveraging accessibility services for remote control and credential theft.

CERT Polska has dissected a sophisticated multi-stage Android banking trojan targeting Polish users through fake banking applications. The malware chain begins with a lure app branded as "Token U2F Mobilna Ochrona SGB" (an SGB bank security token), which social-engineers victims into installing a hidden second-stage package ("Android V.28.11") and enabling an accessibility service masquerading as "System Update". The outer package (com.junk.knock) uses DexClassLoader to dynamically load an installer from its private directory, which then extracts and installs payload_grass.apk (com.core.town). This second-stage APK is itself another loader that hides the final implant inside a fake JPEG asset (qkcCg.jpg), transformed with RC4-like encryption keyed by "sDjCM".

Once fully deployed, the final-stage implant registers with the command-and-control infrastructure at jeliornic.it.com and receives per-device API credentials via Firebase Cloud Messaging. The malware exhibits comprehensive remote-access capabilities including keylogging, UI tree capture, overlay injection for credential harvesting, screen streaming via websocket sessions, gesture injection, clipboard manipulation, and operator-driven remote control through a binary protocol. The accessibility service requests broad permissions (typeAllMask, gesture performance, window content retrieval) and implements web-inject overlays with custom JavaScript to keep credential fields visible during input capture.

The campaign demonstrates operational maturity through its multi-layer obfuscation (runtime loading, nested APK embedding, encrypted assets), comprehensive telemetry (tracking 10+ event types including app launches, permission grants, accessibility enablement), and robust command infrastructure supporting at least 24 distinct operator commands delivered via FCM and websocket channels. CERT Polska attributes this SGB-branded variant to the broader FvncBot campaign based on shared infrastructure (jeliornic.it.com), identical staging architecture, and consistent implant design patterns observed across multiple Polish bank-themed lures.

## Mentioned in this report

- Malware: FvncBot
- Campaigns: FvncBot

Source reporting: https://cert.pl/en/posts/2026/03/fvncbot-analysis

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/22a45c29-95b0-48d6-97cc-187f9d9059e0/fvncbot-financial-services.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
