Skip to content
ThreatCluster

FvncBot Malware Targets Android Users, Stealing Financial Data

First seen 6 Dec 2025, 16:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

FvncBot is a new Android banking malware first observed on November 25, 2025. It is designed to capture keystrokes, record screens, and inject fake login pages into banking applications, primarily affecting users of mBank in Poland. The malware spreads through a fake application disguised as a security tool.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track FvncBot and MBank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed