SpySolr
SpySolr is an Android malware family referenced as a predecessor or parent family of the BTMOB Android remote access trojan. Multiple sources in the provided content state that BTMOB evolved from SpySolr, and some assessments describe BTMOB as a successor to the CraxsRAT, CypherRAT, and SpySolr families. The content does not provide a standalone technical profile of SpySolr itself, but it does tie SpySolr to Android spyware/RAT activity through detections such as Android/Spy.Spysolr.A and through reporting that BTMOB was first described as an offshoot or variant of SpySolr. SpySolr is also mentioned in reporting that links this malware lineage to the threat actor alias EVLF/@craxso. High-confidence details in the content about direct SpySolr behavior, infection vector, targeting, or indicators of compromise are otherwise currently not available.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
IOCs tracked for this family
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older Android malware from which BTMOB evolved.
Referenced only as the malware family from which BTMOB is described as an offshoot.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Earlier malware from which BTMOB evolved.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.