Albiriox is an Android malware-as-a-service family used for mobile financial fraud and full on-device fraud. It is widely described as an Android banking trojan with remote-access functionality, and is also characterized as an Android RAT because it provides real-time control of infected devices. The malware has been associated with Russian-speaking cybercrime operators and was observed emerging in late 2025 with continued development thereafter.
Albiriox targets Android devices and focuses on banking, fintech, payment, trading, and cryptocurrency applications, with reporting consistently noting a hardcoded target set of more than 400 apps. Its core tradecraft relies on abuse of Android Accessibility features to obtain extensive visibility and control over the victim device. Documented capabilities include live screen streaming, VNC-like remote control, UI hierarchy capture, automated interaction with on-screen elements, keylogging, notification interception, phishing overlays, and black-screen or fake system-update overlays used to conceal attacker activity while fraudulent actions are performed.
The malware is designed to let operators conduct transactions from the victim’s own device session, enabling fraud downstream of normal authentication controls. This on-device model can bypass protections such as MFA and server-side anomaly checks because the attacker operates within a legitimate authenticated mobile session. Albiriox has also been reported to capture credentials, PINs, passwords, SMS messages, one-time passcodes, and other sensitive data exposed through notifications or on-screen interaction.
Persistence and anti-removal are notable features. Reported mechanisms include foreground services, boot-triggered execution, scheduled tasking, wake locks, and logic that interferes with user attempts to uninstall or disable the malware. Some analyses also describe Accessibility-based viewing modes intended to bypass Android screen-capture protections used by financial applications.
Observed delivery commonly involves social engineering and sideloaded Android applications rather than exploitation of Android vulnerabilities. Reported lures include fake retail, banking, and reward-themed apps, fraudulent app-store pages, SMS-based phishing, WhatsApp-delivered links, and staged droppers that request permission to install additional applications. Multi-stage deployment and obfuscation have been repeatedly noted, including use of packers or crypting services to reduce static detection.
Albiriox represents the commercialization of advanced mobile fraud tooling, lowering the barrier for affiliates to perform credential theft and real-time account abuse against financial and cryptocurrency users. It also creates enterprise risk in bring-your-own-device environments because compromise of a personal Android device used for work can expose corporate sessions, messages, and cloud-access workflows without directly compromising enterprise infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.
A new Android malware named Albiriox is being offered on cybercrime forums by Russian-speaking threat actors... Albiriox is a banking trojan designed for on-device fraud (ODF), enabling attackers to take control of compromised mobile devices to carry out fraudulent transactions from the victim’s cryptocurrency or banking applications.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"use of the Overlay Attack technique... System Update Overlay... Black Screen Overlay... Targeted Application Overlay"
“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies.
“...custom Builder that integrates the well‑known Golden Crypt crypting service, enabling Albiriox to be packaged in a ‘Fully Undetectable’ form.”
Once active, the Albiriox malware registers an Accessibility service and hands the operator live control. It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
Once active, the Albiriox malware registers an Accessibility service and hands the operator live control. It streams the screen VNC-style, shows fake login overlays, and captures PINs, patterns, and passwords.
The Albiriox malware skips HTTP. Instead, it opens raw TCP sockets and trades JSON messages, each framed with a four-byte length prefix.
"persistent communication channel with its C2 infrastructure using an unencrypted TCP Socket connection"
"Once this permission is granted, the application installs the final payload Albiriox on the compromised device."
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a malware family reportedly affiliated with the GoldenCrypt crypting service provider.
Android banking trojan/RAT delivered via a UniCredit-branded dropper. It abuses Accessibility services, uses overlays, intercepts SMS and OTPs, provides VNC-like remote control, resists removal, and enables on-device account takeover and fraudulent bank transfers.
Android banking malware cited as using similar techniques and targeting a large number of finance apps.
This packer was also used in Albiriox.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.