Multiple active malware campaigns are using trojanized installers and social engineering—rather than software vulnerabilities—to gain initial access and then deploy credential theft or remote-control capabilities. Intel 471 reported a new Android banking trojan dubbed FvncBot targeting Polish mobile banking users by impersonating an mBank “security” app; the dropper prompts installation of an additional “Play” component and then abuses Android Accessibility Services for persistence and control, enabling keylogging, screen capture, and hidden VNC-style remote interaction to facilitate fraudulent transactions.
Separately, Cyderes described an ongoing, large-scale piracy-channel campaign where cracked game installers hide behind a legitimate-looking Ren’Py launcher tracked as RenEngine, which decrypts and launches subsequent stages and introduces HijackLoader via techniques including DLL side-loading and module stomping; observed final payloads include ACR Stealer (and in some cases Vidar) to exfiltrate browser credentials, cookies, and crypto wallet data. Cybereason detailed a different installer-themed operation in Chinese-speaking communities delivering ValleyRat/Winos 4.0 attributed to Silver Fox APT, notable for using the rare “PoolParty Variant 7” process injection (abusing Windows I/O completion ports and ZwSetIoCompletion() after duplicating a handle from Explorer.exe) plus a strengthened watchdog mechanism via injection into Explorer.exe and UserAccountBroker.exe to maintain persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A report published on February 6, 2026 described the RenEngine loader as using a stealthy multi-stage execution chain to bypass security controls. No further incident timing or victim details were provided in the reference.
Intel471 reported that FvncBot appears to have an original codebase rather than being derived from leaked banking trojan source code, suggesting a new developer group. The disclosure detailed its use of Accessibility Services, hidden VNC, keystroke logging, screen capture, WebSocket-based command and control, and data exfiltration capabilities.
The Silver Fox-linked ValleyRat campaign was found to use the rare PoolParty Variant 7 process-injection technique, abusing Windows I/O Completion Ports and Explorer.exe handles to run code inside trusted processes. Researchers also noted a watchdog persistence mechanism and attempts to disrupt Qihoo 360 security products.
Cybereason Security Services reported a campaign targeting Chinese-speaking users with trojanized software installers, including a fake LINE installer that delivered the ValleyRat (Winos 4.0) remote access trojan. The activity was assessed as linked to the Silver Fox APT.
On November 25, 2025, researchers observed a malicious Android app masquerading as an mBank security tool and targeting mobile banking customers in Poland. The app served as a loader for the newly identified FvncBot trojan and used social engineering to get victims to install an additional component for persistence and evasion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.