Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

New Albiriox Android Malware Developed by Russian Cybercriminals

Albiriox is a banking trojan offered under a malware-as-a-service model for $720 per month.

Android malware

A new Android malware named Albiriox is being offered on cybercrime forums by Russian-speaking threat actors, according to online fraud management company Cleafy.

Albiriox is a banking trojan designed for on-device fraud (ODF), enabling attackers to take control of compromised mobile devices to carry out fraudulent transactions from the victim’s cryptocurrency or banking applications. 

The malware appears to be under development. It includes remote access functionality that enables real-time control of the compromised Android device, a feature that seems fully operational.

Albiriox can also be used for overlay attacks, which involve displaying phishing pages on top of legitimate applications to trick users into handing over their banking and cryptocurrency credentials. This functionality was still under development when Cleafy researchers analyzed the malware.

Albiriox emerged in September, when its developers started recruiting users for an early version. The trojan has been offered under a malware-as-a-service (MaaS) model since October, at a price of $650 per month for those who bought a subscription in the first week, and $720 per month starting on October 21. 

One of the first Albiriox campaigns targeted users in Austria, tricking them into installing the malware by advertising a fake app for the Penny supermarket. 

Advertisement. Scroll to continue reading.

This fake app served as a dropper designed to trick the victim into granting elevated permissions and then delivering the Albiriox malware itself as the final payload. 

An analysis of the malware revealed that it targets more than 400 applications worldwide, including banking, crypto, fintech, wallet, trading, payments, investment, and gaming apps. 

In order to increase the malware’s chances of evading detection, its developers provide a custom builder that integrates with a crypting service named Golden Crypt.

“The inclusion of Golden Crypt within the builder pipeline suggests that the Albiriox operators are deliberately positioning the malware as a stealth-optimized product, aiming to evade static detection mechanisms and improve the likelihood of successful deployment during the early infection stages, especially relevant given the malware’s reliance on the two-stage delivery and accessibility-based device takeover,” Cleafy researchers explained. 

UPDATE: Google provided the following statement to SecurityWeek:

“Google confirmed that users are protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services.” 

Related: New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages

Related: Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks

Related: Landfall Android Spyware Targeted Samsung Phones via Zero-Day

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.