Infosecurity-Magazine
BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The BTMOB Android remote access trojan (RAT) has been identified as a significant threat, allowing cybercriminals to remotely control infected devices. First documented in February 2025, BTMOB utilizes a malware-as-a-service (MaaS) model, enabling even low-skilled attackers to deploy sophisticated phishing campaigns. The RAT is distributed through phishing sites masquerading as popular services, leading victims to install malicious APKs. Once installed, BTMOB exploits Android's Accessibility Services to gain extensive permissions, facilitating data exfiltration, screen capture, and device control. ESET researchers noted that BTMOB's commercial packaging lowers barriers for entry into cybercrime, with a reported $5,000 lifetime license. The malware has already been adapted to impersonate local institutions in various countries, including Argentina. As variants can be rapidly generated, defenders are advised to remain vigilant and implement robust mobile security measures.
Key Points: • BTMOB is a powerful Android RAT enabling remote control of infected devices. • The malware is distributed via phishing campaigns targeting users in Brazil and beyond. • Its MaaS model allows low-skilled attackers to create custom payloads without coding.