Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign
A brand monitoring alert led D3Lab to uncover a fraudulent Android malware campaign abusing a major Italian banking brand. The campaign uses a fake reward landing page and a Telegram bot to convince victims to install a malicious APK. Technical analysis revealed a self-contained dropper delivering an embedded second-stage Android banking RAT identified as Albiriox, with Accessibility abuse, overlay capabilities, SMS interception, and custom TCP command-and-control infrastructure.
