BTMOB: A stealthy RAT burrowing deep into Android devices

https://web-assets.esetstatic.com/wls/2026/05-26/btmob-android-malware.jpg

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

26 May 2026 • 6 min. read

Our recent review of threat detections in Brazil surfaced BTMOB, an Android remote access trojan (RAT) that is less notable for detection volume than for the damage it can wreak. The combination of phishing-led delivery, ready-made app-building tooling and device takeover capabilities makes BTMOB a threat to watch well beyond Brazil or Latin America.

BTMOB at a glance

First describedin February 2025, BTMOB has evolved from the SpySolr malware. Unlike banking trojans, which “only” aim to steal people’s financial credentials or intercept their financial transactions, BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it. The RAT is also sold with an APK builder interface, allowing anyone to generate...

Copyright of this story solely belongs to welivesecurity.com. To see the full text click HERE

Read more