BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns

BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns

First seen 27 May 2026, 13:13 UTC Infosecurity-MagazineGbhackersCybersecuritynewsFeeds.FeedburnerDarkreading+5 88% similarity 71.0

Article Content

Browse articles
ThreatCluster

The BTMOB Android remote access trojan (RAT) has been identified as a significant threat, allowing cybercriminals to remotely control infected devices. First documented in February 2025, BTMOB utilizes a malware-as-a-service (MaaS) model, enabling even low-skilled attackers to deploy sophisticated phishing campaigns. The RAT is distributed through phishing sites masquerading as popular services, leading victims to install malicious APKs. Once installed, BTMOB exploits Android's Accessibility Services to gain extensive permissions, facilitating data exfiltration, screen capture, and device control. ESET researchers noted that BTMOB's commercial packaging lowers barriers for entry into cybercrime, with a reported $5,000 lifetime license. The malware has already been adapted to impersonate local institutions in various countries, including Argentina. As variants can be rapidly generated, defenders are advised to remain vigilant and implement robust mobile security measures.

Key Points: • BTMOB is a powerful Android RAT enabling remote control of infected devices. • The malware is distributed via phishing campaigns targeting users in Brazil and beyond. • Its MaaS model allows low-skilled attackers to create custom payloads without coding.

ThreatCluster AI

Timeline

2025-02-01
BTMOB first documented
ESET researchers identified BTMOB as a new Android RAT with extensive capabilities.
Infosecurity-Magazine
2026-01-01
Free BTMOB files advertised on dark web
A dark web forum briefly offered BTMOB files for free, highlighting its potential for rapid distribution.
Infosecurity-Magazine
2026-05-26
ESET warns about BTMOB's spread
ESET released a report detailing BTMOB's phishing distribution methods and capabilities.
Infosecurity-Magazine
2026-05-27
Gbhackers reports on BTMOB's capabilities
Gbhackers highlighted BTMOB's ability to hijack Android phones and its ease of deployment.
Gbhackers
2026-05-27
Cybersecuritynews covers BTMOB's evolution
Cybersecuritynews reported on BTMOB's rapid evolution and its implications for cybersecurity.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story