Skip to content
BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns

BTMOB Android RAT Enables Remote Control of Devices via Phishing Campaigns

First seen 27 May 2026, 13:13 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 28, 2026 at 12:59 UTC
  • BTMOB is a powerful Android RAT enabling remote control of infected devices.
  • The malware is distributed via phishing campaigns targeting users in Brazil and beyond.
  • Its MaaS model allows low-skilled attackers to create custom payloads without coding.

The BTMOB Android remote access trojan (RAT) has been identified as a significant threat, allowing cybercriminals to remotely control infected devices. First documented in February 2025, BTMOB utilizes a malware-as-a-service (MaaS) model, enabling even low-skilled attackers to deploy sophisticated phishing campaigns. The RAT is distributed through phishing sites masquerading as popular services, leading victims to install malicious APKs. Once installed, BTMOB exploits Android's Accessibility Services to gain extensive permissions, facilitating data exfiltration, screen capture, and device control. ESET researchers noted that BTMOB's commercial packaging lowers barriers for entry into cybercrime, with a reported $5,000 lifetime license. The malware has already been adapted to impersonate local institutions in various countries, including Argentina. As variants can be rapidly generated, defenders are advised to remain vigilant and implement robust mobile security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 115d ago How this analysis works

Timeline

2025-02-01
BTMOB first documented
ESET researchers identified BTMOB as a new Android RAT with extensive capabilities.
Infosecurity-Magazine
2026-01-01
Free BTMOB files advertised on dark web
A dark web forum briefly offered BTMOB files for free, highlighting its potential for rapid distribution.
Infosecurity-Magazine
2026-05-26
ESET warns about BTMOB's spread
ESET released a report detailing BTMOB's phishing distribution methods and capabilities.
Infosecurity-Magazine
2026-05-27
Gbhackers reports on BTMOB's capabilities
Gbhackers highlighted BTMOB's ability to hijack Android phones and its ease of deployment.
Gbhackers
2026-05-27
Cybersecuritynews covers BTMOB's evolution
Cybersecuritynews reported on BTMOB's rapid evolution and its implications for cybersecurity.
Cybersecuritynews

More articles in this cluster (10)

Following this threat?

Track Btmob in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed