BTMOB is an Android remote access trojan (RAT) and malware-as-a-service offering first identified in February 2025 and described as derived from the SpySolr malware family. It is marketed as a no-code or low-skill platform that lets operators generate customized malicious APKs and phishing lures, lowering the barrier to entry for cybercriminals. Reporting indicates it has been promoted via an open-web portal, Telegram, and social media, with pricing described in different reports as a lifetime license around $5,000 plus support fees, and in one report with alternative subscription and source-code pricing.
BTMOB is primarily distributed through phishing campaigns and fake Android app stores or counterfeit Google Play-style pages. Observed lures have impersonated streaming and IPTV services, cryptocurrency-related services, GPT Trade, and Argentine public-sector or tax-themed entities such as AFIP. In May 2026, campaigns distributed BTMOB through apps presented as IPTV or streaming platforms offering World Cup broadcasts. It has also been observed as a payload dropped in other Android malware campaigns, including newer BeatBanker variants.
Once installed, BTMOB abuses Android Accessibility Services to obtain elevated privileges and silently grant itself additional permissions. Reported capabilities include remote control of the device, unlocking devices, executing commands, reading messages, displaying victim information, accessing cameras, capturing screenshots, screen or activity recording, keylogging, GPS tracking, file and data exfiltration, and credential theft via HTML injections or overlay-style phishing when targeted apps are opened. Later reporting also noted capture of Alipay PINs. Researchers describe it as enabling full-device takeover rather than only banking fraud.
BTMOB activity has been observed particularly in Brazil and broader Latin America, but its localization and builder features make it adaptable to other regions. It has been linked in reporting to campaigns targeting banking and payment users and to MaaS-style commercialization rather than a single clearly attributed threat actor. One report states ESET believes BTMOB is the successor to CraxsRAT, CypherRAT, and SpySolr, while multiple other reports specifically describe it as evolved from SpySolr.
Known detection names mentioned in the content include MSIL/BtmobRat, Android/Spy.Agent.EED, Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, Android/Agent.FQK, Android/TrojanDropper.Agent.NES, Android/TrojanDropper.Agent.NDK, Android/Spy.Spysolr.A, Android/Spy.Agent.EUG, Android/Spy.Agent.EWN, Android/Spy.Agent.FFE, Android/Spy.Agent.FFL, and Android/TrojanDropper.Agent.NBO. Reported indicators include the domain arbsniper.com; IPs 178.156.177.192, 191.101.131.250, and 195.160.221.203; and sample SHA-256 hashes 58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94 and 0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35. Reporting also notes BTMOB-related files briefly appeared on a dark web forum in January 2026, raising concerns about leakage, resale, and wider secondary-market adoption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands in order to divert them to fraudulent application repositories containing malicious Android applications.
Malware primarily distributes itself through phishing campaigns and fraudulent applications masquerading as legitimate online services... In order to achieve operational success, BTMOB will continue to rely heavily on phishing-driven infection chains designed to maximize the trust of the user base.
BTMOB... enables operators to remotely monitor, manipulate, and control compromised devices... The BTMOB establishes communication with attacker-controlled command-and-control infrastructure... allowing the operator to remotely manage the compromised device and maintain persistent access
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands... Additionally, attacks have been observed that are tailored to align with local institutions and government entities, including operations impersonating Argentine tax and public sector agencies as lures.
These include the ability to exfiltrate a range of sensitive data, capture screenshots, record activity on the device, and ultimately take remote control of it.
BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.
BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes
The BTMOB establishes communication with attacker-controlled command-and-control infrastructure with these privileges, allowing the operator to remotely manage the compromised device and maintain persistent access
Some variants can download additional modules, extending capabilities based on each campaign’s goals.
Intel 471 highlighted activity involving BTMOB, an Android remote access trojan offered through a malware-as-a-service model. The malware was promoted as compatible with Android versions 12 through 16 and included capabilities such as reading messages, executing commands, displaying victim information and accessing device cameras.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan offered as a malware-as-a-service platform. It is distributed via phishing campaigns and fraudulent apps, abuses Android Accessibility Services to gain elevated privileges, connects to attacker-controlled C2 infrastructure, and enables remote device control, persistence, credential theft, monitoring, and fraud-oriented activity.
Android remote access trojan offered via a malware-as-a-service model. It can read messages, execute commands, display victim information, and access device cameras, and was distributed through fake IPTV/streaming apps themed around World Cup broadcasts.
Related Articles: ... BTMOB Android malware service generates custom phishing payloads
Android remote access malware sold as a malware-as-a-service kit with a built-in APK builder. It enables full-device takeover, exfiltrates sensitive data, captures screenshots, records device activity, abuses Android Accessibility Services for elevated permissions, and allows attackers to remotely control infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.