FvncBot Android trojan impersonates Polish bank SGB
CERT Polska uncovered an SGB-branded Android banking trojan (FvncBot) that uses a multi-stage loader chain and abused accessibility services for full device takeover.
CERT Polska analyzed a new sample of the FvncBot campaign, an ongoing operation targeting Polish banking customers with fake bank applications. The analyzed sample masquerades as an SGB "Token U2F Mobilna Ochrona" app and uses social engineering to convince victims to sideload a hidden second-stage component disguised as a system update ("Android V.28.11"), then to grant it accessibility permissions under the pretense of activating a "Play Component". Once granted, the app registers with an attacker-controlled backend and begins full remote-control operation.
Technically, the campaign uses a three-stage delivery chain: an outer lure APK dynamically loads an installer via DexClassLoader, which drops a visible second-stage APK (com.core.town) that itself unpacks a hidden, RC4-encrypted asset disguised as a JPEG to reveal the final implant dex. The final payload is a fully-featured accessibility-based RAT supporting keylogging, UI-tree exfiltration, screen capture/streaming via WebSocket, clickable overlays with WebView JavaScript injection for credential capture, gesture/touch injection, clipboard manipulation, and a binary C2 protocol supporting numerous operator commands (app upload, permission requests, polling/heartbeat control, notification spoofing). Devices register to a backend at jeliornic.it.com and are tracked with per-device API keys and IDs.
CERT Polska notes that this SGB-themed sample shares the same staging architecture, backend infrastructure, and implant design as previously analyzed FvncBot samples impersonating other Polish banks, confirming it as another branch of the same ongoing campaign rather than an isolated incident. No distribution vector (e.g., phishing site, SMS, or ad) has been confirmed as of the analysis date, though the campaign's design (fake caller/lure flow) is consistent with vishing-assisted installation.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/fvncbot-analysis
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free