logo

BTMOB: A stealthy RAT burrowing deep into Android devices

ID: 7b24dd30-d4c2-5061-8e2a-39966b3db744

STIX ID: report--7b24dd30-d4c2-5061-8e2a-39966b3db744

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-27

...
...

BTMOB is a commercially available Android RAT that evolved from SpySolr and is distributed via phishing sites and fake app stores; it abuses Android Accessibility Services to gain elevated permissions, enables full device takeover (data exfiltration, screenshots, remote control), and is marketed with an APK builder that lowers the bar for attackers. The report documents active campaigns (Brazil/Argentina), lists IPs and SHA256 indicators, ESET detection names, and provides mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.