PULSE NAME
Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets
WHITE AlienVault 2025-12-03 Modified: 2025-12-04
19
IOCs
MEDIUM VOLUME
Albiriox is a newly identified Android malware offered as Malware-as-a-Service, likely managed by Russian-speaking threat actors. It employs a two-stage deployment chain using dropper applications and packing techniques to evade detection. The malware exhibits advanced On-Device Fraud capabilities, enabling remote control, screen manipulation, and real-time interaction with infected devices. Albiriox targets over 400 global financial and cryptocurrency applications, combining VNC-based remote access and overlay attack mechanisms. The malware's sophisticated features include device takeover, real-time interaction, and unauthorized operations while remaining undetected. Its MaaS model and ongoing development suggest potential for rapid adoption among threat actors seeking efficient mobile fraud tools.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Albiriox
Indicators of Compromise (19)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 61b59eb41c0ae7fc94f800812860b22a 2025-12-03
FileHash-MD5 b6bae028ce6b0eff784de1c5e766ee33 2025-12-03
FileHash-MD5 f09b82182a5935a27566cdb570ce668f 2025-12-03
FileHash-MD5 f5b501e3d766f3024eb532893acc8c6c 2025-12-03
FileHash-SHA1 1bf53adfede11f6857a95d7b74b40011ff201009 2025-12-03
FileHash-SHA1 731a13bad6316fda68c9d57fb4e562dd0c1130ce 2025-12-03
FileHash-SHA1 b0913e8cbff6a9623cf97a3d4d796ec259e24df7 2025-12-03
FileHash-SHA1 bb2b152adbba554409746bf64d8df71d80a236ea 2025-12-03
FileHash-SHA256 070640095c935c245f960e4e2e3e93720dd57465c81fa9c72426ee008c627bf3 2025-12-03
FileHash-SHA256 5e14181839816bbb4b55badc91f29d382e8d6f603eec2ed8f8b731c35def6b59 2025-12-03
FileHash-SHA256 630b047722d553495def3b8e744f2f621209e1a77389c09a9a972eeb243f9ed8 2025-12-03
FileHash-SHA256 a0c9d6eb1932c96a11301c00cf96ce9767fb11401e090f215f972df06b09a878 2025-12-03
domain google-aplication.download 2025-12-03
domain google-app-download.download 2025-12-03
domain google-app-get.com 2025-12-03
domain google-app-install.com 2025-12-03
domain google-get-app.com 2025-12-03
domain google-get.download 2025-12-03
hostname play.google-get.store 2025-12-03