logo

BTMOB Android malware service generates custom phishing payloads

ID: f451323e-7698-5f54-8142-31de602ec47d

STIX ID: report--f451323e-7698-5f54-8142-31de602ec47d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Bill Toulas

...
...

ESET reports that BTMOB is an Android remote access trojan sold as malware-as-a-service with a user-friendly APK builder for generating custom, localized phishing lures; it targets users (primarily in Brazil and Latin America), abuses Accessibility Services to gain elevated permissions, and provides features for data theft, financial transaction interception, screenshots and remote control, with active distribution via fake Google Play and phishing sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.