s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.albiriox

📛 Threat Title

Malware family: Albiriox

Category: Albiriox First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.albiriox`. Printable name: Albiriox.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.albiriox VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.albiriox

IOC database

Type
domain
Value
apk.albiriox
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.albiriox

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.albiriox

References (1)

Remediations (10)

  • web:cybersecuritycue.com

    Table of Contents Albiriox Android malware is targeting banking and financial apps with credential theft and on-device fraud. Researchers link the new family to Russian-speaking cybercriminals after code and infrastructure analysis. The campaign focuses on sideloaded apps, phishing texts, and fake updates that bypass Google Play safeguards.

  • web:cybersecuritynews.com

    A sophisticated new Android malware family dubbed " Albiriox " has emerged on the cybercrime landscape, offering advanced remote access capabilities as a Malware -as-a-Service (MaaS).

  • web:securityaffairs.com

    Albiriox is new Android MaaS malware enabling on-device fraud and real-time control. It targets 400+ banking, fintech, crypto, and payment apps. Albiriox is a new Android malware sold under a malware -as-a-service model on Russian‑speaking cybercrime forums. It provides advanced capabilities for on-device fraud, screen manipulation, and real-time interaction with infected devices. It also ...

  • web:thehackernews.com

    A new Android malware named Albiriox has been advertised under a malware -as-a-service (MaaS) model to offer a "full spectrum" of features to facilitate on-device fraud (ODF), screen manipulation, and real-time interaction with infected devices. The malware embeds a hard-coded list comprising over 400 applications spanning banking, financial technology, payment processors, cryptocurrency ...

  • web:www.androidauthority.com

    Newly discovered Android malware , Albiriox , can allow hackers to remotely wipe your bank account, even without you noticing it.

  • web:www.cleafy.com

    Albiriox is a newly identified Android malware family offered as a Malware -as-a-Service, and enabling TAs to perform On-Device Fraud through remote control, screen manipulation, and real-time interaction with the infected device. Read more in this report.

  • web:www.jumpsec.com

    ALBIRIOX is sold as a MaaS ( Malware -as-a-Service) on underground cybercrime forums. The initial sales threat was posted on the 14 th October 2025, and since then the developer has been updating the malware frequently, with the last update on the 20 th February 2026. The developer has posted the new ALBIRIOX domain, boasting several of features analysed below, a video showcase, contact ...

  • web:www.malwarebytes.com

    Albiriox is a new family of Android banking malware that gives attackers live remote control over infected phones, letting them quietly drain bank and crypto accounts during real sessions. Researchers have analyzed a new Android malware family called Albiriox which is showing signs of developing rapidly and already has strong capabilities.

  • web:www.pcrisk.com

    Albiriox malware overview The known Albiriox infections relied on a dropper. It presented the victim with a fake "System Update" interface that requested various permissions. Critically, it needed to gain permissions to use the Android Accessibility Services and to install applications from third-parties ("Install Unknown Apps").

  • web:www.rescana.com

    The emergence of the Albiriox Malware -as-a-Service (MaaS) platform marks a significant escalation in the threat landscape for mobile banking, fintech, and cryptocurrency applications. First observed in September 2025, Albiriox is a rapidly evolving Android malware family engineered for On-Device Fraud (ODF), enabling attackers to take full control of infected devices, perform real-time ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.