logo

BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone

ID: c35a2e59-5c22-5a85-801d-0e1cdc1ec633

STIX ID: report--c35a2e59-5c22-5a85-801d-0e1cdc1ec633

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Pierluigi Paganini

...
...

BTMOB is an Android remote access trojan (RAT) sold as a malware-as-a-service with a built-in APK builder that lets non-technical criminals generate localized lures and payloads; it abuses Android Accessibility Services to gain elevated permissions and provides full-device takeover capabilities (data theft, screenshots, screen recording, remote control). Distribution uses phishing to fake app stores and social-media/Telegram sales channels, campaigns have been observed in Latin America, and ESET published indicators of compromise and detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.