BTMOB is an Android remote access trojan (RAT) and malware-as-a-service platform, first identified in early 2025 and derived from the SpySolr family. It provides a no-code APK builder, payload-generation tooling, operator control panels, and supporting server infrastructure, enabling buyers to create localized malicious applications and social-engineering campaigns with limited technical expertise. The ecosystem has evolved from a more centralized service into a fragmented market of resellers, independent operators, and purported source-code variants.
BTMOB is commonly delivered through phishing campaigns that lead victims to counterfeit websites and fake application-store pages impersonating streaming services, cryptocurrency services, government agencies, financial services, and other trusted brands. Victims are induced to sideload a malicious Android application and enable Android Accessibility Services. The malware abuses accessibility privileges to obtain additional permissions and facilitate device control.
On compromised devices, BTMOB supports remote administration and surveillance, including screen capture or recording, keylogging, message and notification access, camera access, device-information collection, command execution, and sensitive-data theft. It can use HTML injection or overlay-style mechanisms to capture credentials and payment-related data, and has been reported to capture PINs in some variants. BTMOB has been observed in campaigns affecting Brazil and other Latin American locations, including Argentina-themed government lures, but its customizable builder and phishing framework permit targeting across regions. Campaigns have also used IPTV and streaming-themed applications as lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands in order to divert them to fraudulent application repositories containing malicious Android applications.
It offers an “exploit chain,” that is, a malicious application, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools.
BTMOB... enables operators to remotely monitor, manipulate, and control compromised devices... The BTMOB establishes communication with attacker-controlled command-and-control infrastructure... allowing the operator to remotely manage the compromised device and maintain persistent access
These include the ability to exfiltrate a range of sensitive data, capture screenshots, record activity on the device, and ultimately take remote control of it.
WebSocket URL pattern ws://<host>:8080/con BTMob WebSocket command-and-control connection
HTTP POST to /yaarsa/private/yarsap_*.php ... /yaarsa/private/createacc.php ... /yaarsa/user/loginbt.php ... /yaarsa/index.php | ws://<host>:8080/con 426 Upgrade Required /yaarsa/server/websocket-server.js
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan offered as a malware-as-a-service platform. It includes a malicious app, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools, with options for private infrastructure, customized builds, and technical support.
Android banking malware platform sold as a service. It is distributed via fake apps, cloned download pages, and social-engineering messages, then used to monitor screens, steal information, abuse permissions, and facilitate account theft and unauthorized financial transfers. The platform includes a malicious Android app, dropper, desktop control panel, server backend, WebSocket-based C2, and an automated APK builder for operators.
Named as a supported Android RAT/botnet payload that can be injected into a PDF-delivered APK by the advertised tool.
Android spyware family listed among the most frequently detected mobile malware in Q2 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.