
Just last week, we learned about a banking malware that exploits accessibility settings on Android to steal your bank credentials in the background. Now, we’re looking at another malware that not only enables remote attacks on Android devices but also allows hackers to share access to your device as part of a subscription service.
Researchers at Cleafy, an online fraud prevention firm, have discovered (via MalwareBytes) a new Android trojanware dubbed “Albiriox.” Just like Sturnus, which we learned about last week, Albiriox is distributed through infected or dummy APKs by luring potential targets into believing they are downloading actual apps. One of the ways that hackers use to achieve that is by creating fake replicas of Google Play Store listings, making users believe they are downloading apps from secure sources when they are actually not. Hackers also lure targets by posting fake promotions and offers, seeking contact details, and then delivering malicious APKs through messaging apps, such as WhatsApp and Telegram.