BTMOB RAT Newly Discovered Android Malware
ID: 639d3071-6553-54ad-ad09-3f3ecf1da496
STIX ID: report--639d3071-6553-54ad-ad09-3f3ecf1da496
Feed Name: Cyble Blog
BTMOB RAT is an advanced Android Remote Access Trojan (RAT), evolved from SpySolr, that is distributed via phishing sites impersonating streaming and mining services and actively marketed on Telegram; it abuses Android Accessibility Services to unlock devices, perform WebView-based credential injection/keylogging, live screen sharing, audio capture, file operations, and other remote-control actions, communicating with operators via WebSocket C2 servers and exhibiting multiple observed commands and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
