logo

Btmob RAT: A New Evolution of Android Malware Targets Users via Phishing Sites

ID: 8bc17819-dce5-5ab0-b46d-624472de433c

STIX ID: report--8bc17819-dce5-5ab0-b46d-624472de433c

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-02-12

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Btmob RAT is a newly discovered Android Remote Access Trojan that leverages Accessibility Services and WebSocket-based C2 to perform credential theft, keylogging, live screen sharing, audio recording, file management, and remote unlocking. It is being distributed via phishing sites (example sample lnat-tv-pro.apk) impersonating streaming and crypto services, connects to a reported C2 at http://server.yaarsa.com/con, and is actively promoted and sold by the actor EVLF on Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.