Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Galaxy enters institutional prediction markets with $10 million Arca trade

June 2, 2026

Veda brings the vault stack behind Kraken DeFi Earn to Privy’s 2,000-plus developer teams

June 2, 2026

DOGE Price Prediction: $0.115 Breakout Imminent as Technical Stars Align

June 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»BTMOB Android RAT Spreads Through No-Code Builder Tooling
BTMOB Android RAT Spreads Through No-Code Builder Tooling
Security

BTMOB Android RAT Spreads Through No-Code Builder Tooling

May 26, 2026No Comments3 Mins Read

An Android remote access trojan (RAT) that lets buyers build their own custom payloads without writing a line of code has been observed spreading through phishing campaigns across Brazil and beyond.

According to new analysis from ESET, the malware, known as BTMOB, pairs phishing-based delivery with a packaged app-building tool and full device takeover.

First documented in February 2025, BTMOB evolved from the earlier SpySolr family and extends beyond a typical banking trojan. Rather than only chasing financial credentials, it can exfiltrate data, capture screenshots, record on-device activity and hand operators remote control of the phone.

Sold as a Product, Built Without Code

What sets BTMOB apart, however, is its commercial packaging. The RAT ships with an APK builder interface that lets buyers quickly generate new payloads and retool phishing lures for specific countries, with no coding required.

Distribution follows a familiar social-engineering pattern. Operators steer victims to phishing sites posing as streaming services, crypto-mining platforms or other recognizable brands, then funnel them toward fake app stores that prompt installation of a malicious APK.

Once on the device, BTMOB abuses Android’s Accessibility Services to escalate its own permissions and grant itself deeper system access without further user interaction.

Researchers have already seen the kit adapted to impersonate local institutions, including campaigns spoofing Argentina’s tax and customs authorities.

Read more on Android MaaS threats: New Android Albiriox Malware Gains Traction in Dark Web Markets

Cheap Licenses, Fast Mutation

BTMOB is sold through a malware-as-a-service (MaaS) model, marketed on a surface-web promotional page that channels buyers to a Telegram operator, alongside seller accounts on X and Instagram.

See also  Scammer steals $743k in fake Linea token rug pull

ESET said a reported $5,000 lifetime license plus a monthly support fee is modestly set against the proceeds of a successful fraud operation, and the service model lowers the bar for less skilled criminals.

That economic logic also makes containment hard. In January 2026, a dark web forum briefly advertised BTMOB files for free before going offline, a reminder that commercial malware rarely stays locked to paying customers once resale and sharing take hold.

Because new variants can be spun up so quickly, ESET warned defenders to expect rapid payload turnover rather than a fixed set of samples.

The company advised users to install apps only from official stores, treat unsolicited links with suspicion and run mobile security software with the same rigor applied to other devices.

“Corporate security teams must make it clear to employees that a single rogue download could expose the company’s crown jewels,” ESET concluded.

Source link

Android BTMOB Builder NoCode RAT Spreads Tooling

Related Posts

V12 Says THORChain Silently Patched Its Critical Bug, Then Told Researchers the Bounty Is ‘Permanently Retired’

June 2, 2026

Fluid Loses $215,000 in Reward System Exploit After Key Compromise

June 2, 2026

Recovery hopes fade as Kelp DAO hacker launders nearly all $220M in stolen funds

June 2, 2026

Chinese Real Estate Developer Murdered in Cambodia After $2M Crypto Ransom Demand

June 2, 2026
Top Posts

Google paves way for AI-produced content with new policy

September 27, 2023

Navigating the barriers to adopting Bitcoin as a business

March 24, 2026

Kroger: 10X P/E, Double-Digit Dividend Growth, Upside Potential

October 2, 2023

Type above and press Enter to search. Press Esc to cancel.