#AndroidRAT
Cyble found Glitch SPY, an Android RAT spread via a fake Polish rental app, using Brokewell as a dropper. It hijacks Accessibility Service for UI control, screen capture, keylogging, SMS theft, and more. #Poland #AndroidRAT #GlitchSPY
Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App
Cyble Research and Intelligence Labs uncovered Glitch SPY, an emerging Android malware family distributed through a fake Polish apartment rental website that tricks users into downloading an APK. The platform abuses Android Accessibility Service, maintains WebSocket-based C&C communication, and supports surveillance, clipboard theft, remote browser abuse, and crypto-clipper activity. #GlitchSPY #BrokewellLoader #tutaj-dompl #sportypointsrewards
www.hendryadrian.com
July 1, 2026 at 10:15 AM
BTMOB shifted from a central Android RAT MaaS into a fragmented market of resellers, source-code vendors, and private server operators, with official prices dropping as listings spread across Telegram. #BTMOB #AndroidRAT #Telegram
Inside the Underground Business of the Android BTMOB RAT malware
BTMOB started as a centrally run Android RAT malware-as-a-service operation, but it has since splintered into a fragmented underground market of resellers, source-code vendors, independent server operators, and impersonators. Flare researchers found that the official channel kept releasing new versions and infrastructure offers while cheaper and sometimes unverified BTMOB listings spread across Telegram and other platforms. #BTMOB #Flare #Telegram
www.hendryadrian.com
August 3, 2026 at 4:45 PM
Leaked Android RAT 'Flying Eagle' fuels 170 servers; successor 'Night Dragon' emerges, escalating mobile malware threats. #CyberSecurity #AndroidRAT #MobileMalware #FlyingEagle thedailytechfeed.com/leaked-andro...
July 29, 2026 at 11:33 AM
RedHook turns on your phone's own Wireless ADB to get shell access - no root, no exploit, no prompt. https://intel.threadlinqs.com/threat/TL-2026-1146 #ThreatIntel #RedHook #Shizuku #AndroidRAT
July 9, 2026 at 6:48 PM
New Glitch SPY Android RAT spreads via a fake rental app, abusing Accessibility to steal data and swap crypto wallet addresses.

#GlitchSPY #Android"/hashtag/AndroidRAT" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#AndroidRAT #Malware #Brokewell #CryptoClipper #Android #Cyble
Glitch SPY Android RAT Spreads Through a Fake Polish Rental App
At a glance Malware family Glitch SPY (Android RAT and builder platform) Threat actor Unattributed; operator unidentified Targets People seeking rental properties in Poland; Polish speakers Delivery Fake Polish rental website pushing an APK via the Brokewell loader Key capabilities Screen streaming, keylogging, SMS and contact theft, crypto-clipper, remote browser, remote control Source Cyble Research and Intelligence Labs TL;DR Cyble uncovered a new Android RAT called Glitch SPY.
securityonline.info
July 3, 2026 at 7:35 AM
BTMOB is an Android malware-as-a-service RAT with a builder for custom phishing APKs, no coding needed. It steals data, hijacks transactions, and spreads via fake Google Play and streaming pages. #BTMOB #Brazil #AndroidRAT
BTMOB Android malware service generates custom phishing payloads
BTMOB is an Android remote access trojan sold as a malware-as-a-service platform with a builder that lets criminals create customized phishing-based payloads without coding. It targets users mainly in Brazil and Latin America, using fake Google Play pages, Accessibility abuse, and multiple theft and remote-control features. #BTMOB #SpySolr #ESET #ANYRUN #Cyble
www.hendryadrian.com
May 29, 2026 at 10:45 AM