Dangerous Android malware quietly targets and empties bank accounts

Robert Haba
Robert Haba
2 min read
Dangerous Android malware quietly targets and empties bank accounts
Trust this source on Google
Add trusted source

We recently reported about another type of banking Android malware that operates in the background and leverages accessibility settings to steal data, including passwords and bank credentials. More malware that allows remote attacks on Android devices and is freely disseminated among hackers as part of a subscription service has just been disclosed.

More banking malware on the loose

Dangerous Android malware quietly targets and empties bank accounts

A new Android trojanware known as Albiriox has been found by researchers at the online fraud protection company Cleafy. Albiriox is disseminated through what are referred to as “dummy” or infected APKs to deceive users into downloading real apps, much as Sturnus, the malware that was discovered last week.

Hackers have tricked people by making phony copies of Google Play Store app listings, as Android Authority noted. As a result, potential victims may think they are downloading an app from a secure site when, in fact, they are not. Additionally, hackers have enticed victims by posting fictitious offers and promotions, requesting contact information, and then distributing the malicious APKs via well-known messaging services like Telegram and WhatsApp.

Read Also: Best Wallpaper Apps for Android in 2026: Free and Premium Picks

The research group claims that hackers in Russia and other nearby regions have been the primary users of these approaches. After being disseminated as a Malware-as-a-Service (MaaS) on dark web forums, it is reported to have lately acquired popularity.

The “install unknown apps” permission on users’ devices is mostly enabled via the APK files that hackers disseminate. The current (and destructive) program containing Albiriox is installed by the dropper app after that is activated.

According to Android Authority, the research organization has already caught over 400 fraudulent apps that target consumers in categories including banking, fintech, digital payments, and cryptocurrencies. Instead than obtaining users’ login credentials, these software versions enable hackers to conduct transactions directly on users’ banking apps.

You should be wary of any strange programs you install, especially if they appear to be connected to banking or any other financial service, as the malware works more covertly and silently. Make sure you have the most recent Play Protect update installed and that you only download apps from the official Google Play Store app.

In terms of updates, make sure your device has the most recent firmware that is supported, as this contains patches for vulnerabilities that have just been discovered. Similarly, Google has published the December Android Security Bulletin.

Samsung Galaxy Watch 8
Samsung Galaxy Watch 8
4.9 / 5.0
Est. Price
$289.99$349.9917% OFF
Buy
Budget
Nothing Phone (4a) Pro
Nothing Phone (4a) Pro
4.5 / 5.0
Est. Price
$494.99$599.0017% OFF
Buy
💎Best Androi Device
Samsung Galaxy S26 Ultra
Samsung Galaxy S26 Ultra
4.9 / 5.0
Est. Price
$1,212.85$1,499.9919% OFF
Buy
Google Pixel 9
Google Pixel 9
5.0 / 5.0
Est. Price
$544.99$799.0032% OFF
Buy
Google Pixel Watch 4
Google Pixel Watch 4
4.8 / 5.0
Est. Price
396.00$499.9921% OFF
Buy
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Learn more in our Affiliate Disclosure.
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Keep Reading

Fresh clues from the Mi Code database point to Xiaomi’s next foldable flagship making a comeback. After scrapping last year’s prototype, the company seems more committed than ever to foldables, with a device that hits a key hardware milestone: Xiaomi’s first foldable running its own silicon. The Foldable Comeback and XRING O3 Mi Code data […]

Xiaomi MIX Fold 5 Spotted with XRING O3 Chipset in Mi Code Leak
NewsRobert HabaApril 26, 2026