Albiriox is an Android malware-as-a-service family used for on-device fraud against banking, fintech, payment, trading, and cryptocurrency applications. It is widely characterized as an Android banking trojan with remote-access functionality, and is also described as a remote access trojan because it gives operators real-time control of infected devices. Reporting places its emergence in late 2025, with evidence suggesting management by Russian-speaking cybercriminal actors and continued active development.
Albiriox is designed to compromise Android devices through social engineering and sideloaded applications rather than exploitation of the operating system. Observed delivery chains have used fake apps, fraudulent app-store style pages, SMS-based lures, WhatsApp-based lure flows, and brand impersonation campaigns. Early campaigns included fake retail-themed Android apps used as droppers to obtain permissions and install the final payload. Later activity also linked Albiriox to impersonation campaigns targeting bank customers through Telegram-mediated distribution.
Once installed, Albiriox abuses Android Accessibility services and related high-risk permissions to achieve deep device control. Its capabilities include real-time screen streaming, UI hierarchy capture, screenshot capture, remote input automation, notification interception, and live keylogging. Operators can issue commands to click, swipe, inject text, simulate hardware buttons, launch or remove applications, and otherwise navigate the device as if physically present. A notable feature is an Accessibility-based VNC mode intended to observe and control protected application interfaces, including cases where apps attempt to prevent conventional screen capture.
Albiriox is built to support credential theft and fraudulent transaction execution directly from the victim’s device session. It monitors foreground applications and can deploy phishing overlays against targeted apps, including banking and cryptocurrency services, to capture PINs, passwords, and other authentication data. It also intercepts notifications and, in some observed reporting, SMS messages and one-time passcodes, enabling operators to work downstream of MFA by abusing already authenticated sessions on the device. This makes the malware particularly effective for on-device fraud because transactions originate from the victim’s legitimate mobile environment.
The malware includes multiple persistence and anti-removal mechanisms. Reported behaviors include boot-start execution, recurring scheduled execution, wake-lock abuse, foreground-service persistence, and aggressive anti-uninstall logic that interferes with attempts to remove the app. It can also display deceptive full-screen overlays, including fake system-update or black-screen interfaces, to conceal attacker activity while remote operations are underway.
Albiriox has been reported to target more than 400 applications globally, spanning banks, fintech platforms, payment services, digital wallets, cryptocurrency exchanges, and trading apps. Although primarily financially motivated, it also presents enterprise risk in bring-your-own-device environments because compromise of a personal Android device used for work can expose corporate credentials, notifications, messages, and active SaaS or cloud sessions without requiring direct compromise of enterprise infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new Android malware named Albiriox is being offered on cybercrime forums by Russian-speaking threat actors... Albiriox is a banking trojan designed for on-device fraud (ODF), enabling attackers to take control of compromised mobile devices to carry out fraudulent transactions from the victim’s cryptocurrency or banking applications.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"use of the Overlay Attack technique... System Update Overlay... Black Screen Overlay... Targeted Application Overlay"
It hides inside the first APK, split across decoy files with fake image extensions, then rebuilt on the device through AES decryption and GZIP.
“...custom Builder that integrates the well‑known Golden Crypt crypting service, enabling Albiriox to be packaged in a ‘Fully Undetectable’ form.”
Once active, the Albiriox malware registers an Accessibility service and hands the operator live control. It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
Once active, the Albiriox malware registers an Accessibility service and hands the operator live control. It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
The Albiriox malware skips HTTP. Instead, it opens raw TCP sockets and trades JSON messages, each framed with a four-byte length prefix.
"persistent communication channel with its C2 infrastructure using an unencrypted TCP Socket connection"
"Once this permission is granted, the application installs the final payload Albiriox on the compromised device."
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan/RAT delivered via a UniCredit-branded dropper. It abuses Accessibility services, uses overlays, intercepts SMS and OTPs, provides VNC-like remote control, resists removal, and enables on-device account takeover and fraudulent bank transfers.
Android banking malware cited as using similar techniques and targeting a large number of finance apps.
This packer was also used in Albiriox.
An Android malware family identified on the same subnet as multiple other malicious operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.