Infosecurity-Magazine BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns
Article Content
- •BTMOB is a powerful Android RAT enabling remote control of infected devices.
- •The malware is distributed via phishing campaigns targeting users in Brazil and beyond.
- •Its MaaS model allows low-skilled attackers to create custom payloads without coding.
The BTMOB Android remote access trojan (RAT) has been identified as a significant threat, allowing cybercriminals to remotely control infected devices. First documented in February 2025, BTMOB utilizes a malware-as-a-service (MaaS) model, enabling even low-skilled attackers to deploy sophisticated phishing campaigns. The RAT is distributed through phishing sites masquerading as popular services, leading victims to install malicious APKs. Once installed, BTMOB exploits Android's Accessibility Services to gain extensive permissions, facilitating data exfiltration, screen capture, and device control. ESET researchers noted that BTMOB's commercial packaging lowers barriers for entry into cybercrime, with a reported $5,000 lifetime license. The malware has already been adapted to impersonate local institutions in various countries, including Argentina. As variants can be rapidly generated, defenders are advised to remain vigilant and implement robust mobile security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Btmob in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Gambling Goblin Targets Brazilian Government Sites for SEO Fraud A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been targeting Brazilian government and educational institutions since mid-2025. This group is connected to the previously documented Earth Berberoka and is using compromised web servers to install malicious Apache modules. These modules reverse-proxy…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…