New BTMOB Malware Lets Attackers Remotely Control Android Devices
ID: 40cbcf45-035e-5066-9613-456fc9f849af
STIX ID: report--40cbcf45-035e-5066-9613-456fc9f849af
Feed Name: cybersecurityNews.com
*Executive summary:* BTMOB is a commoditized Android remote-access trojan (evolving from SpySolr) marketed as a malware-as-a-service with a no-code APK builder and phishing campaign support; it abuses Android Accessibility Services to gain persistent, full-device control (screen viewing, overlays, credential harvesting, file exfiltration), is distributed via fake app stores and localized lures, and has active variants and observable IOCs (IP addresses, SHA256 hashes and vendor detections) that defenders should block and monitor for.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
