Pubblicati da Andrea Draghetti

Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign

A brand monitoring alert led D3Lab to uncover a fraudulent Android malware campaign abusing a major Italian banking brand. The campaign uses a fake reward landing page and a Telegram bot to convince victims to install a malicious APK. Technical analysis revealed a self-contained dropper delivering an embedded second-stage Android banking RAT identified as Albiriox, with Accessibility abuse, overlay capabilities, SMS interception, and custom TCP command-and-control infrastructure.

D3Lab Srl unipersonale – P.IVA IT01865450496 – Italy – Phone: +3905861946434