Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors — Threadlinqs Intelligence
As of 2026-07-24, Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors is a medium-severity malware threat attributed to Albiriox MaaS operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1667 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Attribution: Albiriox MaaS operator · FINANCIAL
Malwarebytes' 'Beyond the Play Store' report highlights how Android threats spread outside official channels: Albiriox, a Malware-as-a-Service on-device-fraud RAT first observed in September 2025 that
In July 2026, Malwarebytes published 'Beyond the Play Store: How Android threats really spread,' documenting that a large share of Android malware infections originate outside the official Google Play Store, through sideloading, SMS phishing (smishing) links, third-party websites, and archive-bundled installers, as well as through supply-chain compromises of previously legitimate Play Store apps.
The centerpiece malware family cited is Albiriox, an Android Remote Access Trojan and banking Trojan-as-a-service first identified by Cleafy Labs and reported publicly by Malwarebytes and multiple outlets (SecurityAffairs, eSecurityPlanet, Hackread, PCrisk, AndroidHeadlines) in December 2025. Albiriox is operated by a Russian-speaking threat-actor collective as a Malware-as-a-Service offering, first surfacing in a private Telegram beta in September 2025 before a public launch on Russian-speaking cybercrime forums in October 2025, priced at $650/month rising to $720/month after October 21, 2025. Unlike traditional banking trojans that phish credentials for later account takeover, Albiriox performs on-device fraud (ODF): it executes fraudulent transactions live, in real time, directly on the victim's own device and within the victim's own authenticated banking/crypto session, evading many server-side fraud-detection controls that rely on device/IP reputation.
Albiriox's deployment chain is two-stage. A dropper application impersonates a legitimate service (observed masquerading as 'Penny Market,' a discount retail brand, and as fake Google Play install pages) and displays a fraudulent 'System Update' overlay to social-engineer the victim into granting the 'Install Unknown Apps' permission, after which it silently installs the second-stage Albiriox payload, itself obfuscated with JSONPacker and optionally crypted through a third-party 'Golden Crypt' service integrated into the actor's custom APK builder and explicitly marketed as fully-undetectable (FUD) against antivirus engines.
Once installed, Albiriox abuses Android's Accessibility Services as its primary capability vector, enabling two parallel remote-control/streaming modes: a standard VNC-like screen mirror, and an Accessibility-Service-based 'AC VNC' mode that captures the screen through the accessibility layer, allowing operators to view and interact with banking/crypto apps that set FLAG_SECURE to block conventional screenshot/screen-recording APIs — effectively bypassing that Android privacy protection. Through the Accessibility Service, the RAT can perform arbitrary UI actions (click, swipe, type text, navigate back/home/recents, power controls), conceal fraudulent activity from the victim behind full-screen black or blank overlays, capture the device unlock/phone password (get_phone_password / clear_phone_password commands), and manage installed applications (launch, uninstall, enumerate). Communication with its command-and-control server uses a raw, unencrypted TCP socket on port 5555, exchanging JSON-formatted commands; sessions are authenticated via a handshake carrying hardware ID, device model, and Android OS version, and kept alive with a ping/pong heartbeat. A C2 server for a documented sample was identified at 194.32.79.94:5555.
Albiriox's target list is hardcoded in an AppInfos class and spans more than 400 applications across traditional banking, fintech, payment processors, cryptocurrency exchanges, digital wallets, and trading platforms globally. A targeted-application overlay module — impersonating individual bank/crypto login screens to harvest credentials — was observed under active development at time of reporting, using generic templates rather than app-specific phishing pages, indicating the family is still maturing.
Distribution of Albiriox evolved across the observed campaign: an initial wave used direct APK downloads from a fake Google Play clone page; a subsequent wave used German-language SMS phishing (smishing) messages targeting victims in Austr
Weaknesses (CWE)
CWE-506, CWE-494, CWE-807
Target sectors: finance, banking, fintech, cryptocurrency, consumer, retail
Target regions: austria, germany, Europe, Global
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1444, T1476, T1475, T1541, T1624, T1626, T1406, T1628, T1629, T1417