#BTMOB
🚨 BTMOB turns Android phishing into no‑code device takeover— abusing Accessibility to hijack screens, steal credentials, and bypass 2FA.

🌐 spoofguard.io/blog/en/spoo...

#AndroidSecurity #PhishingAlert #BTMOB #CyberThreat

Try it for FREE. 🆓
Spoofing Detection: BTMOB Turns Android Devices Into Fraud Tools | Spoofguard.io
✓ Spoofing detection helps organizations identify phishing infrastructure behind Android threats like BTMOB. Learn how the malware works and how defenders can respond.
spoofguard.io
August 20, 2026 at 9:12 AM
BTMOB Androidマルウェアサービスがカスタムフィッシングペイロードを生成
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
BTMOB Android malware service generates custom phishing payloads
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.
www.bleepingcomputer.com
June 3, 2026 at 7:06 AM
“BTMOB” RAT Demonstrates Deep Persistence on Android Devices A recent analysis uncovered BTMOB , a stealthy Android remote access trojan designed to maintain deep persistence and evade detectio...

#Mobile #Threat #Watch #Series

Origin | Interest | Match
“BTMOB” RAT Demonstrates Deep Persistence on Android Devices
BTMOB is a stealthy Android RAT that maintains deep persistence, enabling extensive control and data theft while evading detection. Learn about its implications for mobile security.
zimperium.com
June 5, 2026 at 1:29 PM
Notícia da SecurityOnline

"BTMOB RAT: Cuidado com Aplicativos Falsos de Streaming e Mineração de Criptomoedas" #bolhasec
BTMOB RAT: Beware of Fake Streaming and Crypto Mining Apps
Learn about BTMOB RAT, a new Android Remote Access Trojan targeting users through phishing sites and malicious apps.
securityonline.info
February 17, 2025 at 9:30 PM
May 28, 2026 at 2:06 PM
Inside the Underground Business of the Android BTMOB RAT malware

Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sale…
#hackernews #news
Inside the Underground Business of the Android BTMOB RAT malware
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
www.bleepingcomputer.com
August 4, 2026 at 4:15 PM
BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone
BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone
BTMOB sells Android full-device takeover as a kit. It steals data, records screens, hands attackers remote control for $5K lifetime
securityaffairs.com
May 29, 2026 at 9:55 AM
Blog: "Nuevo malware BTMOB controla remotamente dispositivos Android"
Nuevo malware BTMOB controla remotamente dispositivos Android
Blog sobre informática, tecnología y seguridad con manuales, tutoriales y documentación sobre herramientas y programas
blog.elhacker.net
May 28, 2026 at 8:02 AM
BeatBanker and BTMOB trojans: infection techniques and how to stay safe | Kaspersky official blog
BeatBanker and BTMOB trojans: infection techniques and how to stay safe
How to protect yourself from the BeatBanker Android trojan, which steals cryptocurrency, hijacks your hardware for crypto mining, and swipes all your data.
www.kaspersky.co.uk
March 12, 2026 at 3:24 AM
BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators #Android #AndroidEcosystem #AndroidTrojan
BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators
 The Android remote access trojan known as BTMOB most likely began as a centralized malware-as-a-service operation but transformed into a wider ecosystem, with resellers, source code buyers, rogue operators, and possibly even impersonators, according to the Flare researchers. BTMOB is a remote access trojan for Android devices that takes the form of malware-as-a-service. It offers an “exploit chain,” that is, a malicious application, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools. All of the components may be purchased in various combinations, depending on the chosen subscription plan. Some of the options include private infrastructure, customized builds, and technical support. The Flare researchers analyzed thousands of relevant forum and chat threads to document BTMOB’s activity and distribution channels.  They tracked the malware’s progress from its first appearances in mid-2025 to the present day. In their findings, the researchers observed that while an official channel was distributing the service and its components, other purportedly independent channels and forums sold subscriptions, reseller panels, code, and even alternative versions of the malware under the same name. In particular, the official account announced the V2 of the malware for rent or sale for $700 per month, $3,000 for a lifetime subscription or $5,000 with additional monthly payments for the private infrastructure and support. Less than a month later, the same account announced technical issues and claimed that over 4,000 devices were connected to BTMOB’s servers.  According to the researchers, the account advertised a full source code and setup instructions for BTMOB for $20,000. The package included PHP and Node.js server components, a VB.NET control panel and Java Android code. The advertised source-code price later fell to $10,000 in May 2025. Additionally, they noticed that the Spanish/Portuguese Telegram channel had an issue between two admins, one of whom left the project. The main channel then announced that from now on, all the administrators would function independently.  It also stated that one of them, based in Brazil, had bought the source code and was running his own fork of BTMOB. After that, the secondary market appeared and started advertising much cheaper alternatives to the official subscription. In particular, one Telegram campaign announced the lifetime access to version 4.1.2 and 4.2 of BTMOB for $500 and purported RAT and server source code for $1,500. Other channels and forums also offered subscriptions, reseller panels, source code, and lifetime accounts for different prices and conditions.   It is unclear whether the accounts offering the alternative versions of BTMOB are legitimate or not, as many of them could have used pirated materials or have been scams. For example, the official account warned all their partners that there is only one official BTMOB channel and that other accounts do not represent the company and are not affiliated with it.  Nevertheless, the official account advertised the V4.1 release in February 2026 and V4.5 in April 2026. According to the announcement, the subscription for the private server hosting of several accounts costs about $1,200 lifetime account, a $3,000, and the source code for the server itself costs $7,000.
dlvr.it
August 21, 2026 at 3:03 PM
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and messages that look like routine customer support. Once installed, it can give criminals a path to watch screens, steal information, and interfere with banking activity. The danger is not limited to one malicious app or one country. BTMob is sold as a service, allowing different operators to build and distribute their own versions with local language lures, familiar brands, and payment-focused scams. That model makes campaigns harder to track because the people running them may share code but use separate servers. Analysts at QuimeraX identified a broad, live infrastructure behind the operation after examining leaked BTMob source packages and exposed servers. Their findings show how a once more centralized Android remote-access tool developed into a franchised fraud platform that lowers the effort needed to launch device-takeover campaigns. The reported activity includes highly tailored attacks in Brazil, where criminals used WhatsApp messages, stolen personal details, fake loyalty offers, and follow-up phone calls to persuade targets to sideload an Android package. BTMOB distributed via a fake iNat TV site (Source – QuirmeraX) The combination turns a familiar chat into a convincing route for financial theft, much like the tactics behind  fake KYC banking scams . QuimeraX said in a report shared with Cyber Security News (CSN) that for banks, mobile providers, and consumers, the impact is a widening pool of campaigns that can be adapted. A fraudulent app may look different from one week to the next, while its underlying control system and device permissions remain capable of enabling account theft and unauthorised transfers. BTMob Fraud-as-a-Service Platform A Shodan search for BTMob’s distinctive fake error page found 1,402 hosts on port 3000. Researchers verified several systems as full BTMob command-and-control servers, including one host that exposed web, database, remote desktop, and WebSocket services. The platform packages the malicious Android app, a dropper, a desktop control panel, a server backend, and an automated APK builder. An operator can enter an app name, icon, server address, and requested permissions, then receive a ready-to-share package. This assembly-line setup resembles other  paid Android spyware services  that package infection tools for buyers rather than requiring them to write code. BTMOB platform architecture (Source – QuirmeraX) The source review also points to a reseller system that can create accounts and activation codes, helping the operation spread beyond its original developer. BTMob is linked to the earlier CraxsRAT and SpySolr families, but its value to criminals lies in the business model: source code, branding options, and infrastructure can be reused by many independent groups. The exposed setup helps defenders, but it does not reveal how many victims were infected or what data was stolen. Fake Stores and Social Engineering Victims are commonly led to install BTMob outside official app stores. QuimeraX documented pages masquerading as Google Play, package-tracking apps, streaming services, banking security tools, and government services. Such pages display invented ratings and reviews to make the download look safe, a familiar pattern in  fraudulent Play Store downloads . In one observed Brazilian case, attackers began with a WhatsApp profile using a retailer’s branding and accurate victim data. The fake loyalty offer with a binary accept (Source – QuirmeraX) A fake virtual assistant offered a loyalty upgrade, then a caller spent several minutes guiding the target through enabling installations from unknown sources. The malicious APK arrived in WhatsApp shortly after the call, echoing the risk from  fraudulent support call campaigns . Users should treat unsolicited requests to install an APK, enable Accessibility services, or change unknown-app settings as warning signs. Download financial, government, and delivery apps only through verified stores or official websites, and independently contact an organisation using a trusted number if a message or caller claims urgent action is needed. Security teams can hunt for the stable BTMob server patterns and block identified infrastructure, while monitoring unusual WebSocket traffic and sideloaded applications. Indicators of Compromise (IoCs):- Type Indicator Description APK file name lnat-tv-pro.apk BTMob v2.5 sample distributed through a phishing site impersonating iNat TV Executable file BTMob.exe VB.NET BTMob operator desktop panel Executable file SolrStarter.exe APK-builder component Executable file SolrWorker.exe APK-builder component Shodan query http.html_hash:-983012381 port:3000 Query used to locate hosts serving the BTMob fake 403 page Shodan query html:"painel de controle elite" Query used to locate associated bypass-panel instances HTML hash -983012381 Fake 403 page fingerprint observed on port 3000 C2 port signature 80, 3000, 3306, 8080, 3389 IIS, Node.js/Express, MySQL, WebSocket, and RDP services associated with confirmed BTMob infrastructure Network pattern HTTP POST to /yaarsa/private/yarsap_*.php BTMob C2 communication pattern for IDS and proxy monitoring WebSocket pattern idf, sidf, cip, itype:"Slr_client" JSON fields associated with BTMob WebSocket traffic WebSocket URL pattern ws://<host>:8080/con BTMob WebSocket command-and-control connection HTTP response 426 Upgrade Required Expected response from the BTMob WebSocket service on port 8080 when reached through regular HTTP Domain server[.]yaarsa[.]com Earlier BTMob command-and-control server Domain btmobrat[.]net BTMob storefront Domain playstoreapps[.]pro RADAR Android processing and bypass platform Domain playstoreap[.]lovable[.]app Fake Google Play Store distribution site Domain rastrear-encomendas2[.]pages[.]dev Fake Rodonaves package-tracking distribution page Domain meusdownloads[.]site Fake Play Store distribution page IP address 77[.]111[.]101[.]24 Confirmed BTMob command-and-control server C2 backend path /yaarsa/private/yarsap_85401.php Master configuration file containing database credentials, crypto keys, and User-Agent data C2 backend path /yaarsa/private/createacc.php Reseller-authenticated account-creation API C2 backend path /yaarsa/user/loginbt.php BTMob operator login panel C2 backend path /yaarsa/user/loginbt3.php BTMob operator login panel with Google Authenticator 2FA C2 backend path /yaarsa/user/login.php Decoy fake-403 redirect page C2 backend path /yaarsa/index.php Decoy fake-403 redirect page C2 backend file /yaarsa/server/websocket-server.js Node.js and WebSocket server component Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stop new phishing & malware before they compromise your business.  Integrate live intel from 15K SOCs around the world The post BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers appeared first on Cyber Security News .
cybersecuritynews.com
August 18, 2026 at 3:20 PM
--Microsoft hints at legal action against disgruntled bug hunter Nightmare Eclipse,
--npm-slop package aimed at Claude users reached 676 downloads,
--Android remote access trojan named BTMOB offered to cybercrims,
--Gentleman ransomware operators used a self-propagating Go-based encryptor, 4/6
May 29, 2026 at 2:47 PM
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
An advanced remote access Trojan is propagating online. Notably, it's delivered via an operator licensing model and features a no-code malware-development interface.
www.darkreading.com
May 28, 2026 at 3:42 PM
The Brazilian threat landscape is so fascinating! Lots of region specific trojans (GoPix etc) and general android malware (BTMOB) having a real impact on Brazilian financial companies.
September 1, 2026 at 7:59 PM
WatchGuard and ESET uncovered active banking trojan campaigns hitting Windows and Android users in Latin America and Europe, with Grandoreiro targeting Portuguese banks and BTMOB spreading via fake app sites. #Portugal #Grandoreiro #BTMOB
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
WatchGuard and ESET found two active banking trojan campaigns targeting Windows and Android users across Latin America and Europe, including Grandoreiro attacks against banks in Portugal and BTMOB infections spread through fake app sites. Both families use phishing, legitimate-service abuse, and anti-analysis techniques to steal credentials and expand their reach. #Grandoreiro...
www.hendryadrian.com
May 28, 2026 at 1:00 AM
Android malware campaign detected.
BeatBanker Android Trojan spreads via fake Google Play Store sites.
Targets crypto apps like Binance and Trust Wallet.
New samples deploy BTMOB Remote Access Trojan.
Follow TechNadu for potatosecurity updates.
#AndroidMalware #Infosec
March 11, 2026 at 5:34 PM
BeatBanker Trojan targets Brazil via phishing sites mimicking Google Play Store, deploying crypto miners and banking modules. Uses audio loops, Accessibility abuse, overlays, and Firebase for C2. #Brazil #AndroidThreat #CryptoMiner
BeatBanker: A dual‑mode Android Trojan
BeatBanker is an Android Trojan campaign that targets users in Brazil via phishing sites impersonating the Google Play Store to deliver a crypto miner and a banking module (recent samples drop the BTMOB RAT instead). It maintains persistence by looping an almost inaudible audio file, abuses Accessibility and overlay capabilities to intercept USDT transactions, and uses Firebase Cloud Messaging for command-and-control. #BeatBanker #BTMOB
www.hendryadrian.com
March 10, 2026 at 11:40 PM
it's never really about the malware, is it.
it's about the phish that gets the click.

we're fighting psychology, not code. and tbh we're getting wrecked.
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to
thehackernews.com
May 28, 2026 at 8:31 AM
BTMOB Rat: detectado no Brasil, vírus para Android permite controle total a criminosos
BTMOB Rat: detectado no Brasil, vírus para Android permite controle total a criminosos
Malware identificado pela ESET permite acesso remoto ao dispositivo e é vendido como produto na internet aberta por US$ 700 por mês.
www.estadao.com.br
September 10, 2026 at 5:15 PM
[ICYMI] Malware BTMOB dijual dengan harga sekitar $5.000 dan dapat dikustomisasi. Pengguna Android harus makin waspada tautan phishing yang menyamar layanan lokal. https://melekmedia.org/artikel/btmob-malware-android-yang-dijual-paketan/
September 1, 2026 at 4:00 PM
PanDa RAT hides inside fake Netflix apps pushed via Facebook ads, then keylogs your banking login. https://intel.threadlinqs.com/threat/TL-2026-2279 #ThreatIntel #PanDa #ShellA #BTMOB
September 2, 2026 at 12:35 AM
[ICYMI] Malware BTMOB dijual dengan harga sekitar $5.000 dan dapat dikustomisasi. Pengguna Android harus makin waspada tautan phishing yang menyamar layanan lokal. https://melekmedia.org/artikel/btmob-malware-android-yang-dijual-paketan/
August 30, 2026 at 12:00 PM