logo

“BTMOB” RAT Demonstrates Deep Persistence on Android Devices

ID: 5661aae7-13e7-53ea-ae1b-a7dc517cff6e

STIX ID: report--5661aae7-13e7-53ea-ae1b-a7dc517cff6e

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-06

...
...

The report describes BTMOB, a sophisticated Android remote access trojan that leverages accessibility services and advanced evasion to maintain deep persistence on infected devices, enabling credential theft, screen monitoring, remote commands, and ongoing surveillance; researchers note it can remain hidden while continuously collecting sensitive data from financial, messaging, and personal apps and recommend behavior-based monitoring, strict permission controls, and continuous mobile threat detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.