logo

BTMOB Malware Allows Cybercriminals to Remotely Hijack Android Phones

ID: c550b3da-2d37-5133-a4d9-6b6072711143

STIX ID: report--c550b3da-2d37-5133-a4d9-6b6072711143

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Divya

...
...

BTMOB is an Android remote-access trojan identified in early 2025 that provides attackers near-complete control of infected devices (data exfiltration, screenshots, user monitoring and remote control). It is distributed through phishing and fraudulent app stores, abuses Android Accessibility Services for elevated permissions and persistence, and is sold as a malware-as-a-service with an APK builder—lowering the barrier for widespread abuse. Researchers have observed region-specific lures and multiple signatures across detection tools; the report includes IP and domain indicators and recommends installing apps only from official stores, avoiding unsolicited links, and deploying mobile security solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.