Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets
Essential information
- Published
- 03/12/2025 20:19
- Modified
- 21/12/2025 18:24
- Tags
- 2025-12-03 albiriox android banking trojan cryptocurrency evasion techniques maas on-device fraud overlay attacks rat vnc
- Related entities
- 4 observables, 7 techniques (mitre), 1 malware, 7 others
Description
Albiriox is a newly identified Android malware offered as Malware-as-a-Service, likely managed by Russian-speaking threat actors. It employs a two-stage deployment chain using dropper applications and packing techniques to evade detection. The malware exhibits advanced On-Device Fraud capabilities, enabling remote control, screen manipulation, and real-time interaction with infected devices. Albiriox targets over 400 global financial and cryptocurrency applications, combining VNC-based remote access and overlay attack mechanisms. The malware's sophisticated features include device takeover, real-time interaction, and unauthorized operations while remaining undetected. Its MaaS model and ongoing development suggest potential for rapid adoption among threat actors seeking efficient mobile fraud tools.