SpySolr is an Android malware family associated with remote device compromise and surveillance. It is best known as an antecedent lineage for later Android remote-access malware including BTMOB, and has been cited alongside CraxsRAT and CypherRAT as part of the same evolutionary ecosystem. Available reporting supports that SpySolr is an Android spyware or RAT-family threat used to obtain broad control over infected devices and to support credential theft and financial fraud operations through downstream descendants.
SpySolr has been observed in detections tied to Android spyware classifications, and later malware derived from it abuses Android Accessibility Services to gain elevated privileges, maintain persistent access, monitor device activity, steal credentials, capture screen content, and enable real-time remote control. SpySolr’s direct feature set is not fully documented in the available material, but its repeated treatment as a predecessor to full-featured Android remote-access tooling indicates a role in mobile surveillance and post-compromise control.
The family has been linked in public reporting to criminal Android malware development centered on Latin America, especially Brazil, and to a broader commercialized ecosystem in which successor malware is sold or distributed as a service. SpySolr is therefore most accurately characterized as an Android spyware-family precursor to later MaaS-enabled mobile RAT operations rather than as a standalone, extensively documented campaign brand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
1 distinct technique documented for this family, organized by ATT&CK tactic.
Malware primarily distributes itself through phishing campaigns and fraudulent applications masquerading as legitimate online services... In order to achieve operational success, BTMOB will continue to rely heavily on phishing-driven infection chains designed to maximize the trust of the user base.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier malware family linked to BTMob.
Referenced as the malware family from which BTMOB is derived.
Older Android malware from which BTMOB evolved.
Referenced only as the malware family from which BTMOB is described as an offshoot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.