Malware · 109 days ago

BTMOB Becomes a No-Code Android Phishing Factory

BTMOB has moved from a reusable Android RAT into a service that can mass-produce local phishing payloads. The break is scale: buyers do not need to code or localize the lure themselves, so the same campaign can be repackaged for different brands and countries much faster than static defenses age out.

ESET says the malware is now promoted on the clearweb and through Telegram, with subscription and lifetime pricing for an APK builder that generates customized malicious apps. The lures point victims to fake app stores or lookalike service pages, and the app then abuses Android Accessibility Services to gain broad control and hide its activity; activity has been seen mainly in Brazil and Latin America.

That makes this a churn problem, not a single-sample problem. Teams watching Android phishing resistance need to assume localized prompts and payloads can be regenerated cheaply, which keeps the campaign alive even after individual variants are blocked.

Timeline

Sources

6 sources covering this story

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories