Threat reportMalwareTL-2026-1667

Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors

mediumACTIVE

Albiriox Android Banking RAT-as-a-Service and the Barcode (TL-2026-1667), also tracked as Beyond the Play Store report, is a medium-severity malware campaign, first published 2026-07-24. It is attributed to Albiriox MaaS operator with medium confidence, affects Albiriox threat actor (dropper impersonation) Fake 'Penny Market' /, maps to 20 MITRE ATT&CK techniques (T1406, T1414, T1417), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
1Albiriox MaaS operator
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-1667

Threat ID
TL-2026-1667
Also known as
Beyond the Play Store report, Albiriox RAT, Barcode Scanner AdQR incident
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Albiriox MaaS operator
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, banking, fintech, cryptocurrency, consumer, retail
Target regions
austria, germany, Europe, Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in Albiriox Android Banking RAT-as-a-Service and the Barcode

Malware and tooling: Albiriox, Android/Trojan.HiddenAds.AdQR, Golden Crypt, JSONPacker

How Albiriox Android Banking RAT-as-a-Service and the Barcode works

Malwarebytes' 'Beyond the Play Store' report highlights how Android threats spread outside official channels: Albiriox, a Malware-as-a-Service on-device-fraud RAT first observed in September 2025 that abuses Accessibility Services for live VNC-style remote control of 400+ banking, fintech, and crypto apps; and the historical Barcode Scanner app (10M+ installs) that was trojanized via a legitimate December 2020 Play Store update signed with the original developer's certificate. Both cases illustrate sideloading, SMS-phishing links, fake-update social engineering, and abuse of legitimate signing/update mechanisms as primary Android malware distribution vectors.

In July 2026, Malwarebytes published 'Beyond the Play Store: How Android threats really spread,' documenting that a large share of Android malware infections originate outside the official Google Play Store, through sideloading, SMS phishing (smishing) links, third-party websites, and archive-bundled installers, as well as through supply-chain compromises of previously legitimate Play Store apps.

The centerpiece malware family cited is Albiriox, an Android Remote Access Trojan and banking Trojan-as-a-service first identified by Cleafy Labs and reported publicly by Malwarebytes and multiple outlets (SecurityAffairs, eSecurityPlanet, Hackread, PCrisk, AndroidHeadlines) in December 2025. Albiriox is operated by a Russian-speaking threat-actor collective as a Malware-as-a-Service offering, first surfacing in a private Telegram beta in September 2025 before a public launch on Russian-speaking cybercrime forums in October 2025, priced at $650/month rising to $720/month after October 21, 2025. Unlike traditional banking trojans that phish credentials for later account takeover, Albiriox performs on-device fraud (ODF): it executes fraudulent transactions live, in real time, directly on the victim's own device and within the victim's own authenticated banking/crypto session, evading many server-side fraud-detection controls that rely on device/IP reputation.

Albiriox's deployment chain is two-stage. A dropper application impersonates a legitimate service (observed masquerading as 'Penny Market,' a discount retail brand, and as fake Google Play install pages) and displays a fraudulent 'System Update' overlay to social-engineer the victim into granting the 'Install Unknown Apps' permission, after which it silently installs the second-stage Albiriox payload, itself obfuscated with JSONPacker and optionally crypted through a third-party 'Golden Crypt' service integrated into the actor's custom APK builder and explicitly marketed as fully-undetectable (FUD) against antivirus engines.

Once installed, Albiriox abuses Android's Accessibility Services as its primary capability vector, enabling two parallel remote-control/streaming modes: a standard VNC-like screen mirror, and an Accessibility-Service-based 'AC VNC' mode that captures the screen through the accessibility layer, allowing operators to view and interact with banking/crypto apps that set FLAG_SECURE to block conventional screenshot/screen-recording APIs — effectively bypassing that Android privacy protection. Through the Accessibility Service, the RAT can perform arbitrary UI actions (click, swipe, type text, navigate back/home/recents, power controls), conceal fraudulent activity from the victim behind full-screen black or blank overlays, capture the device unlock/phone password (get_phone_password / clear_phone_password commands), and manage installed applications (launch, uninstall, enumerate). Communication with its command-and-control server uses a raw, unencrypted TCP socket on port 5555, exchanging JSON-formatted commands; sessions are authenticated via a handshake carrying hardware ID, device model, and Android OS version, and kept alive with a ping/pong heartbeat. A C2 server for a documented sample was identified at 194.32.79.94:5555.

Albiriox's target list is hardcoded in an AppInfos class and spans more than 400 applications across traditional banking, fintech, payment processors, cryptocurrency exchanges, digital wallets, and trading platforms globally. A targeted-application overlay module — impersonating individual bank/crypto login screens to harvest credentials — was observed under active development at time of reporting, using generic templates rather than app-specific phishing pages, indicating the family is still maturing.

Distribution of Albiriox evolved across the observed campaign: an initial wave used direct APK downloads from a fake Google Play clone page; a subsequent wave used German-language SMS phishing (smishing) messages targeting victims in Austria, directing them to fraudulent landing pages impersonating the Penny Market retail app, including a fake 'wheel of fortune' promotional page used to harvest Austrian phone numbers, which were then forwarded to an attacker-controlled Telegram bot for further targeting. Distribution has also been reported via WhatsApp-delivered APK files. Multiple lookalike delivery/lure domains impersonating official Google Play download infrastructure were documented: google-app-download[.]download, google-get[.]download, google-aplication[.]download, play.google-get[.]store, google-app-get[.]com, google-get-app[.]com, and google-app-install[.]com.

The Malwarebytes report separately cites the well-documented Barcode Scanner supply-chain incident as an illustration of how a previously trusted, legitimately-signed Play Store app can be weaponized after the fact. The Barcode Scanner app (package com.qrcodescanner.barcodescanner), originally published by LavaBird LTD and installed by roughly 10 million users, shipped a malicious update — version 1.68, released December 4, 2020, with further infected updates through January 5, 2021, published under the name 'The space team' — that added heavily obfuscated code not present in earlier clean versions. Because the update was signed with the same digital certificate as the trusted earlier releases, it inherited full user trust and bypassed both user suspicion and Play Store re-review scrutiny associated with a new/unknown publisher. Malwarebytes classified the payload as Android/Trojan.HiddenAds.AdQR (sample MD5 A922F91BAF324FA07B3C40846EBBFE30); its observed behavior was unwanted automatic default-browser launches and forced ad-fraud redirects with no user interaction, monetizing installed-base traffic through fraudulent advertising impressions. Google removed the app from Play following disclosure, but the malicious code persisted on already-installed devices unless manually uninstalled or removed by security software, since Play Store takedown does not remotely clean existing installs.

Taken together, the two cases in the Malwarebytes report demonstrate that Android's security model is challenged less by Play Store vetting failures at initial publication and more by (1) social-engineering-driven sideloading and permission-granting outside the store entirely, and (2) trust-inheritance abuse, where a compromised developer account or insider pushes a malicious update to an app with an already-established reputation and valid signing certificate, a pattern structurally similar to software supply-chain attacks in the desktop/enterprise ecosystem.

MITRE ATT&CK techniques used in TL-2026-1667

Defense Evasion

T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1629 Impair Defenses

Collection

T1414 Clipboard Data; T1512 Video Capture; T1517 Access Notifications

Credential Access

T1417 Input Capture

Discovery

T1418 Software Discovery; T1421 System Network Connections Discovery; T1426 System Information Discovery

Command and Control

T1437 Application Layer Protocol

Initial Access

T1444 Masquerade as Legitimate Application; T1475 Deliver Malicious App via Authorized App Store; T1476 Deliver Malicious App via Other Means

Persistence

T1541 Foreground Persistence; T1624 Event Triggered Execution

Privilege Escalation

T1626 Abuse Elevation Control Mechanism

Impact

T1643 Generate Traffic from Victim; T1657 Financial Theft

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Albiriox Android Banking RAT-as-a-Service and the Barcode

  • Albiriox threat actor (dropper impersonation) — Fake 'Penny Market' / fake Google Play install pages (Android APK)
    Vulnerable versions: all versions distributed via sideload/SMS lure
  • LavaBird LTD / "The space team" — Barcode Scanner (com.qrcodescanner.barcodescanner)
    Vulnerable versions: 1.68 (2020-12-04) and later updates through 2021-01-05
    Fixed in: app removed from Google Play; no fixed update issued
  • Google — Android OS (Accessibility Services / FLAG_SECURE)
    Vulnerable versions: Android versions supporting Accessibility Service screen-capture bypass of FLAG_SECURE

Remediation for Albiriox Android Banking RAT-as-a-Service and the Barcode

Patches

  • No vendor patch applicable; Barcode Scanner app was removed from Google Play by Google, not patched

Immediate actions

  • Block installation from unknown sources (disable 'Install Unknown Apps' / sideloading) on managed and BYOD Android fleets
  • Block the documented lookalike Google-Play delivery domains at DNS/web proxy: google-app-download[.]download, google-get[.]download, google-aplication[.]download, play.google-get[.]store, google-app-get[.]com, google-get-app[.]com, google-app-install[.]com
  • Block outbound TCP/5555 to 194.32.79.94 and flag any raw-socket JSON C2 beaconing on non-standard ports from mobile endpoints
  • Uninstall Barcode Scanner (com.qrcodescanner.barcodescanner) from any device where it is still installed, regardless of Play Store removal status
  • Alert users to the fake 'System Update' overlay social-engineering pattern used to obtain Install Unknown Apps permission

Workarounds

  • Enable Google Play Protect and ensure it is not disabled on affected devices
  • Restrict banking/crypto app usage to devices without sideloaded APKs or unknown Accessibility Service grants

Longer-term hardening

  • Deploy Mobile Threat Defense (MTD) / EMM policies that restrict or monitor Accessibility Service grants to third-party apps
  • Require banking/fintech apps to detect Accessibility-Service-based screen capture bypass of FLAG_SECURE and step up authentication when detected
  • Implement out-of-band transaction verification (e.g., push-based confirmation on a second device) resistant to on-device-fraud RATs
  • Monitor for signing-certificate reuse combined with sudden permission/behavior changes in app updates as a supply-chain detection signal
  • User awareness training on SMS-phishing (smishing) links, fake Play Store clone pages, and WhatsApp-delivered APKs

Weaknesses (CWE) in Albiriox Android Banking RAT-as-a-Service and the Barcode

CWE-506, CWE-494, CWE-807

Timeline of Albiriox Android Banking RAT-as-a-Service and the Barcode

  • Barcode Scanner v1.68 published to Google Play by 'The space team,' introducing heavily obfuscated malicious code signed with the same certificate as prior clean releases (LavaBird LTD).
  • Further infected Barcode Scanner updates observed through this date, continuing browser-redirect ad-fraud behavior across the ~10 million install base.
  • Malwarebytes publicly discloses the Barcode Scanner supply-chain compromise, classifying the payload as Android/Trojan.HiddenAds.AdQR; Google removes the app from Play.
  • Albiriox RAT enters a private beta/recruitment phase advertised in a Telegram channel by its Russian-speaking developer collective.
  • Albiriox is publicly launched as a Malware-as-a-Service offering on Russian-speaking cybercrime forums, priced at $650/month with a custom APK builder and Golden Crypt integration.
  • Albiriox MaaS subscription price increases from $650/month to $720/month.
  • German-language SMS phishing campaign targeting Austrian victims observed distributing Albiriox via a fake Penny Market landing page and phone-number-harvesting 'wheel of fortune' lure.
  • Cleafy Labs, Malwarebytes, SecurityAffairs, eSecurityPlanet, Hackread, PCrisk, and AndroidHeadlines publish technical analyses of Albiriox, detailing its Accessibility-Service-based dual-VNC architecture, 400+ hardcoded targets, and TCP/5555 C2 protocol.
  • Malwarebytes publishes 'Beyond the Play Store: How Android threats really spread,' citing Albiriox and the historical Barcode Scanner incident as examples of non-Play-Store and supply-chain Android distribution vectors.

Sources cited for Albiriox Android Banking RAT-as-a-Service and the Barcode

Detection coverage for TL-2026-1667

As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1667 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1667

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats