Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Home/CyberSecurity News/BTMOB Malware Remotely Controls Android Devices
CyberSecurity News

BTMOB Malware Remotely Controls Android Devices

Key Takeaways BTMOB is a sophisticated Android Remote Access Trojan (RAT) that grants attackers full remote control over infected mobile devices. It operates under a Malware-as-a-Service (MaaS)...

Marcus Rodriguez
Marcus Rodriguez
May 27, 2026 5 Min Read
70 0

Key Takeaways

  • BTMOB is a sophisticated Android Remote Access Trojan (RAT) that grants attackers full remote control over infected mobile devices.
  • It operates under a Malware-as-a-Service (MaaS) model, featuring a no-code APK builder that enables even novice threat actors to create custom malicious payloads and launch targeted phishing campaigns.
  • First identified in early 2025 as an evolution of the SpySolr family, BTMOB is actively distributed through phishing campaigns mimicking legitimate services and government agencies worldwide.
  • The malware leverages Android Accessibility Services to silently gain extensive permissions, exfiltrate sensitive data, perform screen capture, and execute actions without user interaction.
  • Defenders must prioritize strict app-sourcing policies, user education, and advanced mobile security solutions to counter this rapidly evolving threat.

BTMOB: A New Era of Android Remote Control Malware

A potent new Android malware, dubbed BTMOB, is empowering threat actors of varying skill levels with comprehensive remote control capabilities over compromised smartphones. This sophisticated threat combines a powerful Remote Access Trojan (RAT) engine with an intuitive, no-code campaign builder, significantly lowering the barrier for entry into advanced mobile exploitation.

Table Of Content

  • Key Takeaways
  • BTMOB: A New Era of Android Remote Control Malware
  • From SpySolr to BTMOB: An Evolving Threat
  • Malware-as-a-Service Model and Global Campaigns
  • Delivery Mechanisms and Exploitation
  • Infrastructure IOCs
  • What You Should Do

First documented in early 2025, BTMOB has rapidly evolved into a prominent threat, operating through a Malware-as-a-Service (MaaS) model and fueling active phishing campaigns globally.

From SpySolr to BTMOB: An Evolving Threat

BTMOB represents a significant evolution from the SpySolr malware family. Unlike traditional banking Trojans that primarily target financial data, BTMOB is engineered for extensive device surveillance and complete remote control. Its capabilities are comparable to those typically found in desktop-grade RATs, posing a severe risk to both individual users and corporate environments.

The malware can exfiltrate a broad spectrum of sensitive information, capture screenshots, record on-device activities, and maintain persistent remote access to the compromised device.

BTMOB APK creation tool(source :.welivesecurity)
BTMOB APK creation tool (source: WeLiveSecurity)

Malware-as-a-Service Model and Global Campaigns

A defining characteristic of BTMOB is its commercial availability as a MaaS product, complete with an integrated APK builder. This platform allows purchasers to generate novel malicious Android Package Kit (APK) payloads and craft customized phishing lures tailored to specific countries, all without requiring any coding expertise. This functionality dramatically expands the pool of potential attackers.

The service is advertised on a promotional page accessible via the open web, directing prospective buyers to Telegram channels. Seller accounts are also active on major social media platforms, including X and Instagram.

 X profile linked to the malware(source :.welivesecurity)
X profile linked to the malware (source: WeLiveSecurity)

Reports suggest that lifetime licenses for BTMOB are offered for approximately 5,000 USD. This cost is relatively low when weighed against the substantial illicit profits that successful campaigns can generate.

Delivery Mechanisms and Exploitation

BTMOB predominantly relies on social engineering and phishing for its distribution. Attackers direct victims to deceptive phishing websites that impersonate popular streaming services, cryptocurrency platforms, or other well-known brands. These sites then redirect users to fake app stores hosting the malicious APKs.

Threat actors meticulously adapt their lures to local contexts, including campaigns that spoof tax or government agencies in countries such as Argentina and other regions identified by national cyber agencies.

BTMOB impersonates an Argentine government agency(source :.welivesecurity)
BTMOB impersonates an Argentine government agency (source: WeLiveSecurity)

Upon a victim sideloading the malicious APK, BTMOB requests extensive permissions. It then exploits Android’s Accessibility Services to silently grant itself additional, elevated privileges. Once installed, the malware establishes command-and-control (C2) channels, enabling real-time remote administration of the compromised device.

Operators gain the ability to view the device screen, interact with applications, harvest credentials via overlay attacks, intercept messages, and exfiltrate files and device data. By weaponizing Accessibility Services, BTMOB can manipulate user interface elements, approve permissions, and execute actions without user intervention. It also facilitates overlay attacks against banking and payment applications to steal credentials and one-time passcodes.

Fake app store and malicious apps (source :.welivesecurity)
Fake app store and malicious apps (source: WeLiveSecurity)

Certain BTMOB variants possess the capability to download supplementary modules, thereby expanding their functionalities to align with specific campaign objectives. The MaaS platform’s builder-driven nature allows for the rapid generation of new payload variants, leading to a quick turnover of Indicators of Compromise (IOCs).

Infrastructure IOCs

Domains

  • arbsniper[.]com

IP Addresses

  • 74.125.202[.]103
  • 142.251.183[.]138
  • 173.194.193[.]138
  • 173.194.206[.]106
  • 178.156.177[.]192
  • 191.101.131[.]250
  • 195.160.221[.]203
  • 104.21.64[.]137
  • 173.194.194[.]94
  • 191.96.224[.]87
  • 191.96.225[.]241
  • 191.96.78[.]172
  • 191.96.78[.]28
  • 191.96.79[.]133
  • 191.96.79[.]179
  • 191.96.79[.]41
  • 192.178.209[.]95
  • 200.9.155[.]153
  • 74.125.132[.]95
  • 78.135.93[.]123
  • 79.133.57[.]141
File Hash IOCs

SHA256 Hashes

  • 58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94
  • 0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35
  • A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F
  • 26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A
  • 6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931
  • E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B
  • C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1
  • 6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143
  • 5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D
  • DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39

Detection IOCs

ESET Signatures

  • Android/Agent.FQK
  • Android/TrojanDropper.Agent.NES
  • Android/Spy.Agent.EIJ
  • Android/Spy.Agent.EIK
  • Android/TrojanDropper.Agent.NDK
  • Android/Spy.Spysolr.A
  • Android/Spy.Agent.EUG
  • Android/Spy.Agent.EWN
  • Android/Spy.Agent.FFE
  • Android/Spy.Agent.FFL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Security vendors have observed multiple BTMOB versions, including BTMOB v2.5, emerging in quick succession. This rapid iteration indicates that operators are continuously refining payloads and evasion techniques.

BTMOB offer on the surface web(source :.welivesecurity)
BTMOB offer on the surface web (source: WeLiveSecurity)

According to a report by WeLiveSecurity from ESET, BTMOB samples are detected under various signatures, including MSIL/BtmobRat and multiple Android/Spy.Agent or Android/TrojanDropper classifications. These detections highlight the malware’s connections to earlier SpySolr-based threats. Analysts caution that the circulation of leaked or pirated copies of BTMOB on underground forums could further democratize access to this powerful tool and inspire the development of copycat toolchains.

What You Should Do

  • Enforce Strict App-Sourcing Policies: Only install applications from official and trusted app stores (e.g., Google Play Store). Block or disable sideloading of APKs from unknown sources on organizational devices.
  • Educate Users on Phishing and Social Engineering: Conduct regular awareness training to help users identify and avoid unsolicited links, suspicious messages, and deceptive applications, especially those promising “free” streaming services or high-return crypto investments.
  • Leverage Mobile Security Solutions: Deploy mobile endpoint protection platforms (MEP) or Mobile Threat Defense (MTD) solutions that offer behavioral detection, accessibility-abuse monitoring, and real-time threat intelligence.
  • Treat Smartphones as High-Value Endpoints: Apply the same rigorous security practices to mobile devices as you would to laptops and servers, including comprehensive logging, EDR-style monitoring, and established incident response playbooks.
  • Stay Updated with Threat Intelligence: Given BTMOB’s builder-driven evolution, combine up-to-date Indicators of Compromise (IOCs) with anomaly-based detection methods to effectively counter new variants as they emerge.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical BadHost Vulnerability Exposes AI Agent Servers

Next Post

Motorola Phones’ Preinstalled App Hijacks Amazon App for Affiliate Fraud

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
ChainDrop Worm Steals GitHub, Cloud Credentials via 400+ npm Packages
August 7, 2026
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us