No-Code Android RAT Service Speeds Payload Churn

BTMOB shifts Android malware from a fixed sample to a service that low-skill buyers can repackage fast. The defender is no longer chasing one APK or one lure; they are facing a phishing-and-payload pipeline that can change by country before a static detection catches up. ESET says BTMOB is sold with a no-code APK builder, a malware-as-a-service model, and regional lure support. It is being pushed through phishing sites that lead users to fake app stores, then uses Android Accessibility Services to extend control after installation, with campaigns seen in Brazil and local impersonations including Argentina’s tax and customs authorities. That makes churn part of the threat. The same operator can keep swapping brands, regions, and payloads, so mobile teams need to think in terms of distributed delivery and post-install abuse, not a single frozen artifact.

Part of the PlainSec briefing for 2026-05-27

Sources