A dangerous new malware is targeting bank users. Its name is Albiriox. Hackers use it to access financial accounts. It does not require any OTP for access. The fraud prevention firm Cleafy discovered this threat. It spreads silently through fake mobile applications. Hackers also use cloned Play Store listings. The malware operates as a subscription toolkit. Cybercriminals buy it on dark web platforms.
Hackers use deceptive methods to spread Albiriox. They list malicious files as normal apps. These files have an APK format. Users install these apps manually themselves. Hackers share links through messaging platforms. WhatsApp and Telegram are common sources. Fake app pages also host these files. The Cleafy team noticed a familiar pattern. It matched previous cyber threats they studied.
Albiriox starts as a basic social engineering technique, using a user to essentially trick them into enabling install unknown app trust settings to allow the Albiriox “installer” to insert another legitimized app, but instead of that app it is going to “install” a hidden trojan. The hidden trojan is downloading during that time, no notifications or alerts are given. Once the hidden trojan is completed, it is executed and takes over the device, and starts targeting financial application owners.
The main targets of Albiriox are applications used on a daily basis for digital payments, such as banking and fintech applications. It also targets applications like crypto wallets. The number of fake applications monitored by security researcher has exceeded 400.
Albiriox is a very sophisticated attack method, as the victim will not have any warning or knowledge until they see their money missing from their account after the fact. A model referred to as malware-as-a-service by cybercrime investigations provides this service to the “hackers”.
Essentially, these “hackers” can choose to subscribe to the Albiriox platform (through the website) and take the software to their device, download, and then deploy to attack victims. This is a very common method of cybercrime within Russian cybercriminals; because this way you can easily start your own cyber crime campaign without having to be a true hacker.
There are several simple ways to stay safe online. The first is to avoid using apps from unknown sources. If your phone allows you to install applications from anywhere other than an official store, it is best to keep the option disabled. Make sure you only download and install apps from an official store. Be aware of receiving links via text message.
Think twice before clicking on links that look suspicious. Ensure that you are regularly updating the software on your device with the latest security improvements. Also, make sure you have installed a reputable anti-virus/anti-malware program on your mobile device as an additional layer of protection. Finally, keep up-to-date on all forms of cyber threat information and situations. If you notice any activity that appears to be suspicious, take action immediately.
Also Read: Your Windows PC Has a Hidden Antivirus Tool For Free – Here’s How to Use It