Skip to content

Albiriox

Albiriox is an Android malware-as-a-service family used for mobile financial fraud and full on-device fraud.

Profile source: Mallory opens in a new tab

Albiriox

Family profile

Albiriox is an Android malware-as-a-service family used for mobile financial fraud and full on-device fraud. It is widely described as an Android banking trojan with remote-access functionality, and is also characterized as an Android RAT because it provides real-time control of infected devices. The malware has been associated with Russian-speaking cybercrime operators and was observed emerging in late 2025 with continued development thereafter.

Albiriox targets Android devices and focuses on banking, fintech, payment, trading, and cryptocurrency applications, with reporting consistently noting a hardcoded target set of more than 400 apps. Its core tradecraft relies on abuse of Android Accessibility features to obtain extensive visibility and control over the victim device. Documented capabilities include live screen streaming, VNC-like remote control, UI hierarchy capture, automated interaction with on-screen elements, keylogging, notification interception, phishing overlays, and black-screen or fake system-update overlays used to conceal attacker activity while fraudulent actions are performed.

The malware is designed to let operators conduct transactions from the victim’s own device session, enabling fraud downstream of normal authentication controls. This on-device model can bypass protections such as MFA and server-side anomaly checks because the attacker operates within a legitimate authenticated mobile session. Albiriox has also been reported to capture credentials, PINs, passwords, SMS messages, one-time passcodes, and other sensitive data exposed through notifications or on-screen interaction.

Persistence and anti-removal are notable features. Reported mechanisms include foreground services, boot-triggered execution, scheduled tasking, wake locks, and logic that interferes with user attempts to uninstall or disable the malware. Some analyses also describe Accessibility-based viewing modes intended to bypass Android screen-capture protections used by financial applications.

Observed delivery commonly involves social engineering and sideloaded Android applications rather than exploitation of Android vulnerabilities. Reported lures include fake retail, banking, and reward-themed apps, fraudulent app-store pages, SMS-based phishing, WhatsApp-delivered links, and staged droppers that request permission to install additional applications. Multi-stage deployment and obfuscation have been repeatedly noted, including use of packers or crypting services to reduce static detection.

Albiriox represents the commercialization of advanced mobile fraud tooling, lowering the barrier for affiliates to perform credential theft and real-time account abuse against financial and cryptocurrency users. It also creates enterprise risk in bring-your-own-device environments because compromise of a personal Android device used for work can expose corporate sessions, messages, and cloud-access workflows without directly compromising enterprise infrastructure.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Spoofing

Reported operators

Threat actors

2 named in public reporting
GoldenCrypt

“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.

Russian-speaking threat actors

A new Android malware named Albiriox is being offered on cybercrime forums by Russian-speaking threat actors... Albiriox is a banking trojan designed for on-device fraud (ODF), enabling attackers to take control of compromised mobile devices to carry out fraudulent transactions from the victim’s cryptocurrency or banking applications.

MITRE ATT&CK

Albiriox in ATT&CK

22 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.