SpySolr is an Android malware family referenced as a predecessor or parent family of the BTMOB Android remote access trojan. Multiple reports in the provided content state that BTMOB evolved from, was derived from, or is an offshoot/successor of SpySolr, and some assessments group SpySolr alongside CraxsRAT and CypherRAT as part of the lineage behind BTMOB. The content directly associates SpySolr with Android spyware/RAT activity through detections such as Android/Spy.Spysolr.A. High-confidence details in the provided material about SpySolr itself are limited; most reporting focuses on BTMOB rather than SpySolr’s standalone capabilities, infection vectors, targets, or infrastructure. Based on the content, SpySolr is best characterized as an earlier Android malware family in the same ecosystem that later gave rise to BTMOB and related Android surveillance and remote-control tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
1 distinct technique documented for this family, organized by ATT&CK tactic.
Malware primarily distributes itself through phishing campaigns and fraudulent applications masquerading as legitimate online services... In order to achieve operational success, BTMOB will continue to rely heavily on phishing-driven infection chains designed to maximize the trust of the user base.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the malware family from which BTMOB is derived.
Older Android malware from which BTMOB evolved.
Referenced only as the malware family from which BTMOB is described as an offshoot.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.