# Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors

> Malwarebytes' 'Beyond the Play Store' report highlights how Android threats spread outside official channels: Albiriox, a Malware-as-a-Service on-device-fraud RAT first observed in September 2025 that abuses Accessibility Services for live VNC-style remote control of 400+ banking, fintech, and crypto apps; and the historical Barcode Scanner app (10M+ installs) that was trojanized via a legitimate December 2020 Play Store update signed with the original developer's certificate. Both cases illustrate sideloading, SMS-phishing links, fake-update social engineering, and abuse of legitimate signing/update mechanisms as primary Android malware distribution vectors.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1667
- **ID:** TL-2026-1667
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Albiriox MaaS operator
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In July 2026, Malwarebytes published 'Beyond the Play Store: How Android threats really spread,' documenting that a large share of Android malware infections originate outside the official Google Play Store, through sideloading, SMS phishing (smishing) links, third-party websites, and archive-bundled installers, as well as through supply-chain compromises of previously legitimate Play Store apps.

The centerpiece malware family cited is Albiriox, an Android Remote Access Trojan and banking Trojan-as-a-service first identified by Cleafy Labs and reported publicly by Malwarebytes and multiple outlets (SecurityAffairs, eSecurityPlanet, Hackread, PCrisk, AndroidHeadlines) in December 2025. Albiriox is operated by a Russian-speaking threat-actor collective as a Malware-as-a-Service offering, first surfacing in a private Telegram beta in September 2025 before a public launch on Russian-speaking cybercrime forums in October 2025, priced at $650/month rising to $720/month after October 21, 2025. Unlike traditional banking trojans that phish credentials for later account takeover, Albiriox performs on-device fraud (ODF): it executes fraudulent transactions live, in real time, directly on the victim's own device and within the victim's own authenticated banking/crypto session, evading many server-side fraud-detection controls that rely on device/IP reputation.

Albiriox's deployment chain is two-stage. A dropper application impersonates a legitimate service (observed masquerading as 'Penny Market,' a discount retail brand, and as fake Google Play install pages) and displays a fraudulent 'System Update' overlay to social-engineer the victim into granting the 'Install Unknown Apps' permission, after which it silently installs the second-stage Albiriox payload, itself obfuscated with JSONPacker and optionally crypted through a third-party 'Golden Crypt' service integrated into the actor's custom APK builder and explicitly marketed as fully-undetectable (FUD) against antivirus engines.

Once installed, Albiriox abuses Android's Accessibility Services as its primary capability vector, enabling two parallel remote-control/streaming modes: a standard VNC-like screen mirror, and an Accessibility-Service-based 'AC VNC' mode that captures the screen through the accessibility layer, allowing operators to view and interact with banking/crypto apps that set FLAG_SECURE to block conventional screenshot/screen-recording APIs — effectively bypassing that Android privacy protection. Through the Accessibility Service, the RAT can perform arbitrary UI actions (click, swipe, type text, navigate back/home/recents, power controls), conceal fraudulent activity from the victim behind full-screen black or blank overlays, capture the device unlock/phone password (get_phone_password / clear_phone_password commands), and manage installed applications (launch, uninstall, enumerate). Communication with its command-and-control server uses a raw, unencrypted TCP socket on port 5555, exchanging JSON-formatted commands; sessions are authenticated via a handshake carrying hardware ID, device model, and Android OS version, and kept alive with a ping/pong heartbeat. A C2 server for a documented sample was identified at 194.32.79.94:5555.

Albiriox's target list is hardcoded in an AppInfos class and spans more than 400 applications across traditional banking, fintech, payment processors, cryptocurrency exchanges, digital wallets, and trading platforms globally. A targeted-application overlay module — impersonating individual bank/crypto login screens to harvest credentials — was observed under active development at time of reporting, using generic templates rather than app-specific phishing pages, indicating the family is still maturing.

Distribution of Albiriox evolved across the observed campaign: an initial wave used direct APK downloads from a fake Google Play clone page; a subsequent wave used German-language SMS phishing (smishing) messages targeting victims in Austria, directing them to fraudulent landing pages impersonating the Penny Market retail app, including a fake 'wheel of fortune' promotional page used to harvest Austrian phone numbers, which were then forwarded to an attacker-controlled Telegram bot for further targeting. Distribution has also been reported via WhatsApp-delivered APK files. Multiple lookalike delivery/lure domains impersonating official Google Play download infrastructure were documented: google-app-download[.]download, google-get[.]download, google-aplication[.]download, play.google-get[.]store, google-app-get[.]com, google-get-app[.]com, and google-app-install[.]com.

The Malwarebytes report separately cites the well-documented Barcode Scanner supply-chain incident as an illustration of how a previously trusted, legitimately-signed Play Store app can be weaponized after the fact. The Barcode Scanner app (package com.qrcodescanner.barcodescanner), originally published by LavaBird LTD and installed by roughly 10 million users, shipped a malicious update — version 1.68, released December 4, 2020, with further infected updates through January 5, 2021, published under the name 'The space team' — that added heavily obfuscated code not present in earlier clean versions. Because the update was signed with the same digital certificate as the trusted earlier releases, it inherited full user trust and bypassed both user suspicion and Play Store re-review scrutiny associated with a new/unknown publisher. Malwarebytes classified the payload as Android/Trojan.HiddenAds.AdQR (sample MD5 A922F91BAF324FA07B3C40846EBBFE30); its observed behavior was unwanted automatic default-browser launches and forced ad-fraud redirects with no user interaction, monetizing installed-base traffic through fraudulent advertising impressions. Google removed the app from Play following disclosure, but the malicious code persisted on already-installed devices unless manually uninstalled or removed by security software, since Play Store takedown does not remotely clean existing installs.

Taken together, the two cases in the Malwarebytes report demonstrate that Android's security model is challenged less by Play Store vetting failures at initial publication and more by (1) social-engineering-driven sideloading and permission-granting outside the store entirely, and (2) trust-inheritance abuse, where a compromised developer account or insider pushes a malicious update to an app with an already-established reputation and valid signing certificate, a pattern structurally similar to software supply-chain attacks in the desktop/enterprise ecosystem.

## MITRE ATT&CK

- T1444 Masquerade as Legitimate Application
- T1476 Deliver Malicious App via Other Means
- T1475 Deliver Malicious App via Authorized App Store
- T1541 Foreground Persistence
- T1624 Event Triggered Execution
- T1626 Abuse Elevation Control Mechanism
- T1406 Obfuscated Files or Information
- T1628 Hide Artifacts
- T1629 Impair Defenses
- T1417 Input Capture
- T1418 Software Discovery
- T1426 System Information Discovery
- T1421 System Network Connections Discovery
- T1517 Access Notifications
- T1512 Video Capture
- T1414 Clipboard Data
- T1437 Application Layer Protocol
- T1646 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1643 Generate Traffic from Victim

## Sources

- [Beyond the Play Store: How Android threats really spread](https://www.malwarebytes.com/blog/inside-malwarebytes/2026/07/beyond-the-play-store-how-android-threats-really-spread)
- [New Android malware lets criminals control your phone and drain your bank account](https://www.malwarebytes.com/blog/news/2025/12/new-android-malware-lets-criminals-control-your-phone-and-drain-your-bank-account)
- [Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets](https://www.cleafy.com/cleafy-labs/albiriox-rat-mobile-malware-targeting-global-finance-and-crypto-wallets)
- [Albiriox Android RAT Targets Global Banking and Crypto Users](https://www.esecurityplanet.com/threats/news-android-malware-albiriox/)
- [Emerging Android threat 'Albiriox' enables full on-device fraud](https://securityaffairs.com/185194/malware/emerging-android-threat-albiriox-enables-full-on%E2%80%91device-fraud.html)
- [Newly Sold Albiriox Android Malware Targets Banks and Crypto Holders](https://hackread.com/albiriox-android-malware-targets-banks-crypto/)
- [Albiriox Malware (Android) - Malware removal instructions](https://www.pcrisk.com/removal-guides/34453-albiriox-malware-android)
- [Android Malware Albiriox: Dangerous New Threat That Can Empty Your Bank Account](https://www.androidheadlines.com/2025/12/android-malware-albiriox-dangerous-new-threat-that-can-empty-your-bank-account.html)
- [Barcode Scanner app on Google Play infects 10 million users with one update](https://www.malwarebytes.com/blog/news/2021/02/barcode-scanner-app-on-google-play-infects-10-million-users-with-one-update)
- [Android app joins the dark side, sends malware update to millions](https://www.bleepingcomputer.com/news/security/android-app-joins-the-dark-side-sends-malware-update-to-millions/amp/)
- [Top Barcode Scanner app infected 10 million users with malware](https://hackread.com/barcode-scanner-app-infected-users-malware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1667
