BTMOB RAT is an Android remote access trojan marketed as a malware-as-a-service offering and used in active mobile malware campaigns. It has been identified as a variant or evolution within the SpySolr-related Android malware ecosystem, and some reporting also links it to the broader CraxsRAT and CypherRAT lineage. The malware is designed to provide operators with extensive control over compromised Android devices and to support credential theft, surveillance, and financially motivated abuse.
Observed capabilities include credential harvesting, keylogging, browser password theft, screen monitoring or recording, camera access, GPS or location tracking, audio recording, file handling, command execution, and broad remote device control. Reporting also attributes Accessibility Service abuse and WebView-based credential theft to BTMOB RAT, enabling device takeover and fraud workflows. Campaigns using BTMOB RAT have been associated with financial fraud operations, including abuse of banking and cryptocurrency applications.
BTMOB RAT has been delivered through fraudulent Android app distribution chains, including fake app download pages and multi-stage Android droppers. In notable campaigns, the MiningDropper framework reconstructed and installed BTMOB RAT as a final payload after layered decryption, dynamic code loading, and anti-analysis checks. More recent BeatBanker campaign variants have also replaced an earlier banking module with BTMOB RAT, extending those operations from banking fraud and mining into full remote access and surveillance.
The malware targets Android devices and has been observed in campaigns affecting users across India, Europe, Latin America, and Asia, with some activity specifically targeting Brazilian users through related delivery operations. Its combination of remote administration, credential capture, surveillance, and fraud-enabling features makes it a versatile Android threat used for both espionage-style access and financially motivated crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Recent iterations of the campaign have been found to drop BTMOB RAT instead of the banking module."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
"The initial APK file is packed... libludwwiuh.so... decrypt another ELF..." and "names are encrypted... using XOR (stack strings technique)"
Cyble said that final payload can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real time remote control, screen monitoring, file handling, audio recording, and command execution.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan advertised with capabilities including persistence, permission abuse, disabling Google Play Protect, bypassing banking apps, stealing cryptocurrency and browser passwords, keylogging, screen control, app tracking, location tracking, call/SMS/contact management, and DDoS/crypto-mining features.
An Android remote access trojan delivered by MiningDropper. The content says it can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real-time remote control, screen monitoring, file handling, audio recording, and command execution.
An Android remote access trojan delivered by MiningDropper that supports credential theft, WebView-based injections, keylogging, data exfiltration, abuse of Accessibility Services, device unlocking, simulated user interaction, permission granting, file management, audio recording, and WebSocket-based real-time remote control.
Android remote access trojan used as a payload in BeatBanker campaigns; provides comprehensive remote control, persistence, and surveillance; assessed as an evolution of CraxsRAT/CypherRAT/SpySolr code lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.