logo

BTMOB RAT Newly Discovered Android Malware

ID: 639d3071-6553-54ad-ad09-3f3ecf1da496

STIX ID: report--639d3071-6553-54ad-ad09-3f3ecf1da496

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-06-09

Date Updated: 2026-07-17

...
...

BTMOB RAT is an advanced Android Remote Access Trojan (RAT), evolved from SpySolr, that is distributed via phishing sites impersonating streaming and mining services and actively marketed on Telegram; it abuses Android Accessibility Services to unlock devices, perform WebView-based credential injection/keylogging, live screen sharing, audio capture, file operations, and other remote-control actions, communicating with operators via WebSocket C2 servers and exhibiting multiple observed commands and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.