← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets
Albiriox is a newly identified Android malware offered as Malware-as-a-Service, likely managed by Russian-speaking threat actors. It employs a two-stage deployment chain using dropper applications and packing techniques to evade detection. The malware exhibits advanced On-Device Fraud capabilities, enabling remote control, screen manipulation, and real-time interaction with infected devices. Albiriox targets over 400 global financial and cryptocurrency applications, combining VNC-based remote access and overlay attack mechanisms. The malware's sophisticated features include device takeover, real-time interaction, and unauthorized operations while remaining undetected. Its MaaS model and ongoing development suggest potential for rapid adoption among threat actors seeking efficient mobile fraud tools.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4 / 19 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 61b59eb41c0ae7fc94f800812860b22a | — | 2025-12-03 | |
| FileHash-MD5 | b6bae028ce6b0eff784de1c5e766ee33 | — | 2025-12-03 | |
| FileHash-MD5 | f09b82182a5935a27566cdb570ce668f | — | 2025-12-03 | |
| FileHash-MD5 | f5b501e3d766f3024eb532893acc8c6c | — | 2025-12-03 |