A new Android malware called Albiriox has emerged, offered under a malware-as-a-service (MaaS) model and targeting over 400 financial, banking, fintech, cryptocurrency, and payment applications. The malware is distributed via dropper apps using social engineering lures, such as fake Google Play Store pages, and employs advanced evasion techniques including packing and integration with third-party crypting services. Once installed, Albiriox enables real-time device control, screen manipulation, and on-device fraud, leveraging a VNC-based remote access module and developing overlay systems for credential theft. Initial campaigns have specifically targeted Austrian users with German-language SMS lures, and the malware's infrastructure and forum activity suggest Russian-speaking threat actors are behind its development.
Albiriox was first observed in a closed beta phase in September 2025 and became publicly available as a MaaS offering in October 2025, with a subscription model starting at $650 per month. The malware is rapidly evolving, with early campaigns operated by high-reputation affiliates and a structured approach to development and distribution. Security researchers have highlighted the malware's potential for widespread adoption among cybercriminals seeking scalable tools for mobile fraud, given its advanced capabilities and broad targeting of financial applications. The threat is considered significant due to its ability to bypass mobile security solutions and facilitate large-scale, real-time fraudulent activities on compromised devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Cleafy researchers publicly documented Albiriox's capabilities, including unencrypted TCP command-and-control, dual VNC modes, accessibility-based screen capture that can bypass FLAG_SECURE protections, and multiple overlay techniques for credential theft and fraud concealment. Their disclosure also highlighted the malware's hard-coded targeting of 400+ financial apps and its use as a MaaS platform.
Initial observed campaigns, likely run by a single affiliate, targeted Austrian users with German-language SMS phishing lures and fake Google Play-style pages. The infection chain used a fake 'Penny Market' app as a dropper and later evolved to a WhatsApp-based flow that collected phone numbers and exfiltrated data via a Telegram bot.
After its beta phase, Albiriox began being advertised publicly in October 2025 as a malware-as-a-service offering. Its operators promoted capabilities including VNC-based remote access, overlays, and targeting of more than 400 banking, fintech, payment, trading, and cryptocurrency apps.
Researchers reported that the Android malware-as-a-service Albiriox was first observed in a closed beta on Russian-speaking cybercrime forums. The malware was designed to enable on-device fraud through remote control, accessibility abuse, and credential theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcemalwarebytes.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.