BTMOB Malware Remotely Controls Android Devices
Key Takeaways BTMOB is a sophisticated Android Remote Access Trojan (RAT) that grants attackers full remote control over infected mobile devices. It operates under a Malware-as-a-Service (MaaS)...
Key Takeaways
- BTMOB is a sophisticated Android Remote Access Trojan (RAT) that grants attackers full remote control over infected mobile devices.
- It operates under a Malware-as-a-Service (MaaS) model, featuring a no-code APK builder that enables even novice threat actors to create custom malicious payloads and launch targeted phishing campaigns.
- First identified in early 2025 as an evolution of the SpySolr family, BTMOB is actively distributed through phishing campaigns mimicking legitimate services and government agencies worldwide.
- The malware leverages Android Accessibility Services to silently gain extensive permissions, exfiltrate sensitive data, perform screen capture, and execute actions without user interaction.
- Defenders must prioritize strict app-sourcing policies, user education, and advanced mobile security solutions to counter this rapidly evolving threat.
BTMOB: A New Era of Android Remote Control Malware
A potent new Android malware, dubbed BTMOB, is empowering threat actors of varying skill levels with comprehensive remote control capabilities over compromised smartphones. This sophisticated threat combines a powerful Remote Access Trojan (RAT) engine with an intuitive, no-code campaign builder, significantly lowering the barrier for entry into advanced mobile exploitation.
Table Of Content
First documented in early 2025, BTMOB has rapidly evolved into a prominent threat, operating through a Malware-as-a-Service (MaaS) model and fueling active phishing campaigns globally.
From SpySolr to BTMOB: An Evolving Threat
BTMOB represents a significant evolution from the SpySolr malware family. Unlike traditional banking Trojans that primarily target financial data, BTMOB is engineered for extensive device surveillance and complete remote control. Its capabilities are comparable to those typically found in desktop-grade RATs, posing a severe risk to both individual users and corporate environments.
The malware can exfiltrate a broad spectrum of sensitive information, capture screenshots, record on-device activities, and maintain persistent remote access to the compromised device.

Malware-as-a-Service Model and Global Campaigns
A defining characteristic of BTMOB is its commercial availability as a MaaS product, complete with an integrated APK builder. This platform allows purchasers to generate novel malicious Android Package Kit (APK) payloads and craft customized phishing lures tailored to specific countries, all without requiring any coding expertise. This functionality dramatically expands the pool of potential attackers.
The service is advertised on a promotional page accessible via the open web, directing prospective buyers to Telegram channels. Seller accounts are also active on major social media platforms, including X and Instagram.

Reports suggest that lifetime licenses for BTMOB are offered for approximately 5,000 USD. This cost is relatively low when weighed against the substantial illicit profits that successful campaigns can generate.
Delivery Mechanisms and Exploitation
BTMOB predominantly relies on social engineering and phishing for its distribution. Attackers direct victims to deceptive phishing websites that impersonate popular streaming services, cryptocurrency platforms, or other well-known brands. These sites then redirect users to fake app stores hosting the malicious APKs.
Threat actors meticulously adapt their lures to local contexts, including campaigns that spoof tax or government agencies in countries such as Argentina and other regions identified by national cyber agencies.

Upon a victim sideloading the malicious APK, BTMOB requests extensive permissions. It then exploits Android’s Accessibility Services to silently grant itself additional, elevated privileges. Once installed, the malware establishes command-and-control (C2) channels, enabling real-time remote administration of the compromised device.
Operators gain the ability to view the device screen, interact with applications, harvest credentials via overlay attacks, intercept messages, and exfiltrate files and device data. By weaponizing Accessibility Services, BTMOB can manipulate user interface elements, approve permissions, and execute actions without user intervention. It also facilitates overlay attacks against banking and payment applications to steal credentials and one-time passcodes.

Certain BTMOB variants possess the capability to download supplementary modules, thereby expanding their functionalities to align with specific campaign objectives. The MaaS platform’s builder-driven nature allows for the rapid generation of new payload variants, leading to a quick turnover of Indicators of Compromise (IOCs).
Infrastructure IOCs
Domains
- arbsniper[.]com
IP Addresses
- 74.125.202[.]103
- 142.251.183[.]138
- 173.194.193[.]138
- 173.194.206[.]106
- 178.156.177[.]192
- 191.101.131[.]250
- 195.160.221[.]203
- 104.21.64[.]137
- 173.194.194[.]94
- 191.96.224[.]87
- 191.96.225[.]241
- 191.96.78[.]172
- 191.96.78[.]28
- 191.96.79[.]133
- 191.96.79[.]179
- 191.96.79[.]41
- 192.178.209[.]95
- 200.9.155[.]153
- 74.125.132[.]95
- 78.135.93[.]123
- 79.133.57[.]141
File Hash IOCs
SHA256 Hashes
- 58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94
- 0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35
- A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F
- 26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A
- 6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931
- E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B
- C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1
- 6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143
- 5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D
- DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39
Detection IOCs
ESET Signatures
- Android/Agent.FQK
- Android/TrojanDropper.Agent.NES
- Android/Spy.Agent.EIJ
- Android/Spy.Agent.EIK
- Android/TrojanDropper.Agent.NDK
- Android/Spy.Spysolr.A
- Android/Spy.Agent.EUG
- Android/Spy.Agent.EWN
- Android/Spy.Agent.FFE
- Android/Spy.Agent.FFL
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Security vendors have observed multiple BTMOB versions, including BTMOB v2.5, emerging in quick succession. This rapid iteration indicates that operators are continuously refining payloads and evasion techniques.

According to a report by WeLiveSecurity from ESET, BTMOB samples are detected under various signatures, including MSIL/BtmobRat and multiple Android/Spy.Agent or Android/TrojanDropper classifications. These detections highlight the malware’s connections to earlier SpySolr-based threats. Analysts caution that the circulation of leaked or pirated copies of BTMOB on underground forums could further democratize access to this powerful tool and inspire the development of copycat toolchains.
What You Should Do
- Enforce Strict App-Sourcing Policies: Only install applications from official and trusted app stores (e.g., Google Play Store). Block or disable sideloading of APKs from unknown sources on organizational devices.
- Educate Users on Phishing and Social Engineering: Conduct regular awareness training to help users identify and avoid unsolicited links, suspicious messages, and deceptive applications, especially those promising “free” streaming services or high-return crypto investments.
- Leverage Mobile Security Solutions: Deploy mobile endpoint protection platforms (MEP) or Mobile Threat Defense (MTD) solutions that offer behavioral detection, accessibility-abuse monitoring, and real-time threat intelligence.
- Treat Smartphones as High-Value Endpoints: Apply the same rigorous security practices to mobile devices as you would to laptops and servers, including comprehensive logging, EDR-style monitoring, and established incident response playbooks.
- Stay Updated with Threat Intelligence: Given BTMOB’s builder-driven evolution, combine up-to-date Indicators of Compromise (IOCs) with anomaly-based detection methods to effectively counter new variants as they emerge.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.