Threats Tagged 'on-device fraud'
View all threats tagged with 'on-device fraud'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'on-device fraud'
Click on any threat for detailed analysis and mitigation recommendations
Albiriox is a newly discovered Android RAT malware offered as Malware-as-a-Service, primarily targeting financial and cryptocurrency applications globally. It uses a sophisticated two-stage deployment involving dropper apps and packing to evade detection. The malware enables remote control of infected devices via VNC-based access and overlay attacks, allowing real-time interaction and unauthorized operations such as screen manipulation and device takeover. It targets over 400 financial and crypto wallet apps, facilitating on-device fraud while remaining stealthy. The MaaS model and ongoing development indicate potential rapid spread among cybercriminals. Although no known exploits in the wild are reported yet, its advanced capabilities pose a significant threat to mobile users, especially in finance sectors. The malware is linked to Russian-speaking threat actors and uses multiple fake domains for distribution. European organizations with mobile banking and crypto wallet users are at risk, particularly in countries with high Android usage and financial sector prominence. Mitigation requires targeted detection of dropper apps, user education on app sources, and enhanced mobile endpoint protection. Given its impact on confidentiality, integrity, and availability with ease of exploitation and no user interaction needed post-installation, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:09 UTC Added: 12/04/2025, 11:23:20 UTC |
Albiriox is a newly identified Android banking malware family that enables cybercriminals to remotely control infected devices and conduct financial fraud. It operates as Malware-as-a-Service (MaaS), featuring modular components such as loaders, command modules, and control panels designed specifically for targeting banking, fintech, payment, and cryptocurrency applications. Distributed via fake apps and social engineering, it mimics legitimate brands and app stores to deceive users. The malware abuses Android accessibility features and employs black-screen masking to hide malicious activity. Notably, it can bypass multi-factor authentication and device fingerprinting, increasing its effectiveness. Although currently rated medium severity, its capabilities pose significant risks to user confidentiality and financial integrity. European organizations with mobile banking users are at risk, especially in countries with high Android adoption and fintech usage. Mitigation requires verifying app sources, maintaining updated devices, deploying advanced anti-malware solutions, and educating users about social engineering tactics. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:08 UTC Added: 12/04/2025, 14:44:50 UTC |
Showing 1 to 2 of 2 results