logo

New BTMOB Malware Lets Attackers Remotely Control Android Devices

ID: 40cbcf45-035e-5066-9613-456fc9f849af

STIX ID: report--40cbcf45-035e-5066-9613-456fc9f849af

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Abinaya

...
...

*Executive summary:* BTMOB is a commoditized Android remote-access trojan (evolving from SpySolr) marketed as a malware-as-a-service with a no-code APK builder and phishing campaign support; it abuses Android Accessibility Services to gain persistent, full-device control (screen viewing, overlays, credential harvesting, file exfiltration), is distributed via fake app stores and localized lures, and has active variants and observable IOCs (IP addresses, SHA256 hashes and vendor detections) that defenders should block and monitor for.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.