Technology

Android malware Albiriox abuses 400+ financial apps in on-device fraud and screen manipulation attacks

2025-12-01 15:04
409 views
Android malware Albiriox abuses 400+ financial apps in on-device fraud and screen manipulation attacks

A new MaaS is circulating around the dark web, offering a full service for defrauding Android users.

  1. Pro
  2. Security
Android malware Albiriox abuses 400+ financial apps in on-device fraud and screen manipulation attacks News By Sead Fadilpašić published 1 December 2025

A new MaaS is circulating around the dark web

Comments (0) ()

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Man looking at smartphone Behöver du en VPN till din Android? (Image credit: Shutterstock)
  • New Android MaaS “Albiriox” targets Austrian users’ banking and crypto apps
  • Malware uses fake apps, dropper APKs, and 400+ overlays to steal sensitive data
  • Researchers link campaign to Russian actors; stolen info exfiltrated via Telegram

Android users are being targeted by a new, sophisticated malware-as-a-service (MaaS), aimed at gaining access to their banking and crypto apps and, ultimately, stealing their money and other valuables.

Recently, cybersecurity researchers Cleafy said they saw Android malware named Albiriox being advertised on the dark web.

The tool is apparently offering a “full spectrum” of features, including complete remote control of the target device, and more than 400 hardcoded overlays for different banking, fintech, crypto, and payment apps.

You may like
  • An Android phone being held in the hand This dangerous new Android malware disguises itself as a VPN or IPTV app - so be on your guard
  • An Android phone being held in the hand This devious Android malware spoofs WhatsApp, TikTok and more - here's how to stay safe
  • Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat Watch out, these malicious Android apps have been downloaded 42 million times - and could leave you seriously out of pocket

Fake software updates

The malware is spoofing all kinds of businesses, including PENNY. The attackers would create a fake landing page and Google Play Store app listings pages, and would ask the victims to share their phone numbers. Those that do would get the download link for an .APK file in an SMS or WhatsApp message.

For now, Cleafy says, the scam works only on Austrian phone numbers, but hints that the attack can easily spread to other parts of the world.

The APK is not the malware itself, but rather a dropper.

"The malware leverages dropper applications distributed through social engineering lures, combined with packing techniques, to evade static detection and deliver its payload," Cleafy researchers Federico Valentini, Alessandro Strino, Gianluca Scotti, and Simone Mattia said.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

When installed, the dropper prompts for permissions and asks for a “software update” which is nothing more than the download of the actual payload.

Through Albiriox, the attackers can take over the mobile devices entirely, or they can use the malware as an infostealer, exfiltrating phone numbers, passwords, and other sensitive information. All data is being pulled to a Telegram channel, it was said.

Although attribution is difficult, this seems to be the work of a Russian threat actor. Cleafy says the attackers’ activity on cybercrime forums, the way they speak, and the infrastructure they use, all suggests their Russian origins.

Via The Hacker News

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

TOPICS Malware Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more An Android phone being held in the hand This dangerous new Android malware disguises itself as a VPN or IPTV app - so be on your guard    An Android phone being held in the hand This devious Android malware spoofs WhatsApp, TikTok and more - here's how to stay safe    Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat Watch out, these malicious Android apps have been downloaded 42 million times - and could leave you seriously out of pocket    Trojan New Android RAT uses Near Field Communication to automatically steal money from devices    Android spyware pretends to be Signal or ToTok update to fool victims - here's how to stay safe    A hacker wearing a hoodie sitting at a computer, his face hidden. The 'Swiss army knife' of malware emerges - Hook v3 can do ransomware, keylogging, DDoS, screen capture, and far more    Latest in Security A concept image showing smart industry, data exchange, cloud computing, and the Internet of Things. Security researcher uncovers 17,000 secrets in public GitLab repositories    Cyberattack Millions of footballers see info leaked after French Football Federation suffers data breach    Tor Browser Tor adds another layer to the onion with a new relay encryption algorithm - boosting resilience and security across the board    Users display warnings about the use of artificial intelligence (AI), access to malicious software or threats to online hackers. computer cyber security Warning concept or tech scam. Take extra care shopping for Black Friday deals - experts find thousands of fake websites looking to steal your details    Microsoft Teams Microsoft Teams guest access could let hackers bypass some critical security protections    A shopping cart logo on a laptop screen. Many of us aren't confident we could spot a fake website this Black Friday - so be on your guard    Latest in News Lucia Caminos GTA 6 leak supposedly from former Rockstar animator drops new content clues    Mature man using laptop in a cafe, looking annoyed Windows 11 File Explorer fudge works, I just wish it was fixed properly    ChatGPT Agent Brace yourself, ChatGPT fans – your conversations could get ads soon    The OnePlus 15R, OnePlus Pad Go 2, and OnePlus Watch Lite OnePlus 15R confirmed to get Snapdragon 8 Gen 5 chipset, 165Hz display, and more    The Jet Black Apple Watch Series 10 watch on a grey background Some Apple Watch Series 10 users are reportedly getting free replacements    Man looking at smartphone Android malware Albiriox abuses 400+ financial apps in on-device fraud and screen manipulation attacks    LATEST ARTICLES