Skip to main content
Mallory
MalwareUsed by 2 actors

BTMOB

BTMOB is an Android remote access trojan (RAT) first identified in February 2025 and described as an offshoot or evolution of SpySolr. It is marketed as a malware-as-a-service offering and sold with a no-code APK builder that allows buyers to generate malicious Android apps and customize phishing lures for different countries without programming skills. Reporting cited pricing that included a lifetime license around $5,000 plus support, while other reporting referenced subscription-style pricing and source-code sales. The malware has been promoted via open-web pages, Telegram, and social media accounts.

BTMOB is designed for broad device takeover rather than only banking fraud. Reported capabilities include remote control of infected Android devices, device unlocking, command execution, reading messages, displaying victim information, camera access, screenshot capture, screen or activity recording, keylogging, GPS tracking, file and data exfiltration, and credential theft through HTML injections or overlay-style phishing when targeted apps are opened. Later reporting also noted capture of Alipay PINs. BTMOB abuses Android Accessibility Services to obtain elevated permissions and additional system access after installation.

Observed delivery commonly relies on social engineering and phishing. Victims are directed to fake websites impersonating streaming services, cryptocurrency platforms, government or tax agencies, or counterfeit Google Play pages, and are then prompted to install malicious APKs. Campaigns were observed in Brazil and broader Latin America, including Argentina-themed lures impersonating AFIP. In May 2026, BTMOB was also distributed through apps presented as IPTV or streaming platforms offering World Cup broadcasts. Separate reporting tied BTMOB delivery to fake Google Play Store landing pages for an app named GPT Trade, sometimes alongside a persistence module referred to as UASecurity Miner.

BTMOB has also been observed as a secondary or replacement payload in other Android malware campaigns. More recent BeatBanker iterations reportedly replaced their banking module with BTMOB, enabling total device compromise, screen recording, credential exfiltration, keylogging, camera access, and GPS tracking. Some reports also noted victims infected with a separate BTMOB espionage and remote-control module.

The malware has been associated in reporting with the actor or seller EVLF (@craxso), and one report stated ESET believes BTMOB is the successor to CraxsRAT, CypherRAT, and SpySolr. Additional reporting noted claims of leaked BTMOB-related files or a leaked development toolkit in late 2025 to early 2026, including references to payload source code, builder components, operator panel, and backend elements, raising concern about wider underground adoption.

Known indicators and detections mentioned in the content include detection names such as MSIL/BtmobRat, Android/Spy.Agent.EED, Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, Android/Agent.FQK, Android/TrojanDropper.Agent.NES, Android/TrojanDropper.Agent.NDK, Android/TrojanDropper.Agent.NBO, Android/Spy.Spysolr.A, Android/Spy.Agent.EUG, Android/Spy.Agent.EWN, Android/Spy.Agent.FFE, and Android/Spy.Agent.FFL. Reported infrastructure and sample indicators include the domain arbsniper.com; IPs 178.156.177.192, 191.101.131.250, and 195.160.221.203; and SHA-256 hashes 58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94 and 0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
EVLF

The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.

via the hacker newsthehackernews.com
Go1ano developer

Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.

via threatfabricthreatfabric.com
MITRE ATT&CK

Techniques & procedures

17 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1189Drive-by CompromiseEvidence2

That site redirects victims to a fake app store that looks like Google Play and prompts them to install an APK.

T1566PhishingEvidence5

The infection starts with a phishing message pointing victims to a fake website impersonating a streaming service, a crypto mining platform, or something similarly familiar.

T1566.002Spearphishing LinkEvidence3

Basic phishing security hygiene applies as well, such as treating unsolicited links delivered via email, messaging apps, social media, and targeted advertisements with suspicion and not clicking on anything that even remotely seems like a scam.

Execution

2 techniques
T1204User ExecutionEvidence3

The primary method through which the malware spreads is via social engineering, where users are sent links to bogus websites masquerading as streaming services or cryptocurrency mining platforms.

T1204.002Malicious FileEvidence3

In May 2026, a campaign was identified distributing BTMOB through applications presented as IPTV or streaming platforms offering access to World Cup broadcasts.

Persistence

1 technique
T1546.008Accessibility FeaturesEvidence4

Once installed, BTMOB seeks extensive access to the device by abusing Android Accessibility Services to gain elevated permissions and granting itself further system access and control over the device without additional user interaction.

Privilege Escalation

2 techniques
T1546.008Accessibility FeaturesEvidence4

Once installed, BTMOB seeks extensive access to the device by abusing Android Accessibility Services to gain elevated permissions and granting itself further system access and control over the device without additional user interaction.

T1548Abuse Elevation Control MechanismEvidence3

Once the APK is installed on the device, BTMOB abuses Android Accessibility Services to grant itself elevated permissions without any further user input.

Stealth

1 technique
T1036MasqueradingEvidence5

The infection starts with a phishing message pointing victims to a fake website impersonating a streaming service, a crypto mining platform... That site redirects victims to a fake app store that looks like Google Play... Researchers have already observed campaigns in Argentina impersonating the country’s tax and customs authority, AFIP.

Credential Access

2 techniques
T1056Input CaptureEvidence3

BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.

T1056.001KeyloggingEvidence1

BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes

Collection

5 techniques
T1005Data from Local SystemEvidence2

These include the ability to exfiltrate a range of sensitive data, capture screenshots, record activity on the device, and ultimately take remote control of it.

T1056Input CaptureEvidence3

BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.

T1056.001KeyloggingEvidence1

BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes

T1113Screen CaptureEvidence5

These include the ability to exfiltrate a range of sensitive data, capture screenshots, record activity on the device, and ultimately take remote control of it.

T1125Video CaptureEvidence1

Unlike typical banking trojans, BTMOB offers adversaries a wider range of malicious actions, including ... activity recording...

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence1

Once installed, BTMOB establishes command-and-control channels to allow real-time remote administration of the device.

T1105Ingress Tool TransferEvidence1

Some variants can download additional modules, extending capabilities based on each campaign’s goals.

T1219Remote Access ToolsEvidence6

Intel 471 highlighted activity involving BTMOB, an Android remote access trojan offered through a malware-as-a-service model. The malware was promoted as compatible with Android versions 12 through 16 and included capabilities such as reading messages, executing commands, displaying victim information and accessing device cameras.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence2

BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device...

INDICATORS OF COMPROMISE

IOCs tracked for this family

62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
25 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
37 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app11 days ago
ip.v4●●●●●●●●●●●●View more in app12 days ago
hash.sha256●●●●●●●●●●●●View more in app12 days ago
ip.v4●●●●●●●●●●●●View more in app12 days ago
ip.v4●●●●●●●●●●●●View more in app12 days ago
ip.v4●●●●●●●●●●●●View more in app12 days ago
ACTIVITY FEED

Recent activity

15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

help net securityNews
Jun 8, 2026
Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup - Help Net Security

Android remote access trojan offered via a malware-as-a-service model. It can read messages, execute commands, display victim information, and access device cameras, and was distributed through fake IPTV/streaming apps themed around World Cup broadcasts.

Read more
security affairsNews
May 29, 2026
BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone

Android remote access malware sold as a malware-as-a-service kit with a built-in APK builder. It enables full-device takeover, exfiltrates sensitive data, captures screenshots, records device activity, abuses Android Accessibility Services for elevated permissions, and allows attackers to remotely control infected devices.

Read more
dark readingNews
May 28, 2026
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model

An Android remote access Trojan distributed via a malware-as-a-service model with a no-code APK builder. It enables attackers to create malicious banking apps and supports sensitive data exfiltration, screenshot capture, activity recording, abuse of Android Accessibility Services, and full remote control of infected devices.

Read more
the hacker newsNews
May 27, 2026
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Android remote access trojan sold as malware-as-a-service. It spreads via phishing and fake app sites, abuses Android accessibility services, enables remote control, screenshot capture, keylogging, device unlocking, and credential theft through HTML injections, including capture of Alipay PINs.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching62

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping17

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.