Last seven days
- First activity
- Aug 7, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Albiriox is an Android malware-as-a-service family used for on-device fraud against banking, fintech, payment, trading, and cryptocurrency applications.
Profile source: Mallory opens in a new tabAlbiriox
Albiriox is an Android malware-as-a-service family used for on-device fraud against banking, fintech, payment, trading, and cryptocurrency applications. It is widely characterized as an Android banking trojan with remote-access functionality, and is also described as a remote access trojan because it gives operators real-time control of infected devices. Reporting places its emergence in late 2025, with evidence suggesting management by Russian-speaking cybercriminal actors and continued active development.
Albiriox is designed to compromise Android devices through social engineering and sideloaded applications rather than exploitation of the operating system. Observed delivery chains have used fake apps, fraudulent app-store style pages, SMS-based lures, WhatsApp-based lure flows, and brand impersonation campaigns. Early campaigns included fake retail-themed Android apps used as droppers to obtain permissions and install the final payload. Later activity also linked Albiriox to impersonation campaigns targeting bank customers through Telegram-mediated distribution.
Once installed, Albiriox abuses Android Accessibility services and related high-risk permissions to achieve deep device control. Its capabilities include real-time screen streaming, UI hierarchy capture, screenshot capture, remote input automation, notification interception, and live keylogging. Operators can issue commands to click, swipe, inject text, simulate hardware buttons, launch or remove applications, and otherwise navigate the device as if physically present. A notable feature is an Accessibility-based VNC mode intended to observe and control protected application interfaces, including cases where apps attempt to prevent conventional screen capture.
Albiriox is built to support credential theft and fraudulent transaction execution directly from the victim’s device session. It monitors foreground applications and can deploy phishing overlays against targeted apps, including banking and cryptocurrency services, to capture PINs, passwords, and other authentication data. It also intercepts notifications and, in some observed reporting, SMS messages and one-time passcodes, enabling operators to work downstream of MFA by abusing already authenticated sessions on the device. This makes the malware particularly effective for on-device fraud because transactions originate from the victim’s legitimate mobile environment.
The malware includes multiple persistence and anti-removal mechanisms. Reported behaviors include boot-start execution, recurring scheduled execution, wake-lock abuse, foreground-service persistence, and aggressive anti-uninstall logic that interferes with attempts to remove the app. It can also display deceptive full-screen overlays, including fake system-update or black-screen interfaces, to conceal attacker activity while remote operations are underway.
Albiriox has been reported to target more than 400 applications globally, spanning banks, fintech platforms, payment services, digital wallets, cryptocurrency exchanges, and trading apps. Although primarily financially motivated, it also presents enterprise risk in bring-your-own-device environments because compromise of a personal Android device used for work can expose corporate credentials, notifications, messages, and active SaaS or cloud sessions without requiring direct compromise of enterprise infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
A new Android malware named Albiriox is being offered on cybercrime forums by Russian-speaking threat actors... Albiriox is a banking trojan designed for on-device fraud (ODF), enabling attackers to take control of compromised mobile devices to carry out fraudulent transactions from the victim’s cryptocurrency or banking applications.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.