# FvncBot Android trojan impersonates Polish bank SGB

Published: 2026-03-30 · Severity: medium · Sectors: financial-services
Canonical: https://vorant.io/reports/908c42ed-4e96-5558-8de0-28d2ed8b2b36/fvncbot-android-trojan-impersonates-polish-bank-sgb

> CERT Polska uncovered an SGB-branded Android banking trojan (FvncBot) that uses a multi-stage loader chain and abused accessibility services for full device takeover.

CERT Polska analyzed a new sample of the FvncBot campaign, an ongoing operation targeting Polish banking customers with fake bank applications. The analyzed sample masquerades as an SGB "Token U2F Mobilna Ochrona" app and uses social engineering to convince victims to sideload a hidden second-stage component disguised as a system update ("Android V.28.11"), then to grant it accessibility permissions under the pretense of activating a "Play Component". Once granted, the app registers with an attacker-controlled backend and begins full remote-control operation.

Technically, the campaign uses a three-stage delivery chain: an outer lure APK dynamically loads an installer via DexClassLoader, which drops a visible second-stage APK (com.core.town) that itself unpacks a hidden, RC4-encrypted asset disguised as a JPEG to reveal the final implant dex. The final payload is a fully-featured accessibility-based RAT supporting keylogging, UI-tree exfiltration, screen capture/streaming via WebSocket, clickable overlays with WebView JavaScript injection for credential capture, gesture/touch injection, clipboard manipulation, and a binary C2 protocol supporting numerous operator commands (app upload, permission requests, polling/heartbeat control, notification spoofing). Devices register to a backend at jeliornic.it.com and are tracked with per-device API keys and IDs.

CERT Polska notes that this SGB-themed sample shares the same staging architecture, backend infrastructure, and implant design as previously analyzed FvncBot samples impersonating other Polish banks, confirming it as another branch of the same ongoing campaign rather than an isolated incident. No distribution vector (e.g., phishing site, SMS, or ad) has been confirmed as of the analysis date, though the campaign's design (fake caller/lure flow) is consistent with vishing-assisted installation.

## Mentioned in this report

- Malware: FvncBot
- Campaigns: FvncBot campaign

Source reporting: https://cert.pl/en/posts/2026/03/fvncbot-analysis

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/908c42ed-4e96-5558-8de0-28d2ed8b2b36/fvncbot-android-trojan-impersonates-polish-bank-sgb.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
