logo

From Lock Screen to Wallets: BTMOB RAT Now Targets Alipay PINs

ID: ee572989-e3b9-5b48-aed6-c8306bd6798d

STIX ID: report--ee572989-e3b9-5b48-aed6-c8306bd6798d

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-04-23

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zimperium zLabs analyzed a multi-version campaign of BTMOB RAT spyware (v2.5–v3.2) delivered via deceptive phishing sites and droppers impersonating legitimate apps and services; the malware abuses Android Accessibility and encrypted overlay assets to capture lock-screen credentials and Alipay PINs, performs keylogging, screen/audio capture and exfiltrates data to C2 servers, with 32 droppers and 44 payloads identified and associated MITRE ATT&CK techniques and IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.