Malware · 109 days ago
BTMOB has moved from a reusable Android RAT into a service that can mass-produce local phishing payloads. The break is scale: buyers do not need to code or localize the lure themselves, so the same campaign can be repackaged for different brands and countries much faster than static defenses age out.
ESET says the malware is now promoted on the clearweb and through Telegram, with subscription and lifetime pricing for an APK builder that generates customized malicious apps. The lures point victims to fake app stores or lookalike service pages, and the app then abuses Android Accessibility Services to gain broad control and hide its activity; activity has been seen mainly in Brazil and Latin America.
That makes this a churn problem, not a single-sample problem. Teams watching Android phishing resistance need to assume localized prompts and payloads can be regenerated cheaply, which keeps the campaign alive even after individual variants are blocked.
6 sources covering this story
BTMOB Android malware service generates custom phishing payloads
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.
BTMOB RAT Spreads Across Brazil, LatAm Via MaaS Model
An advanced remote access Trojan is spreading; it's delivered via an operator licensing model and features a no-code malware-development interface.
New BTMOB Android Malware Enables Full Device Takeover
Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Grandoreiro and BTMOB campaigns targeted Europe and Latin America in 2026, increasing banking malware risks.
BTMOB Android RAT Spreads Through No-Code Builder Tooling
BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures
BTMOB: A stealthy RAT burrowing deep into Android devices
The BTMOB malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise.
Part of the PlainSec briefing for 2026-05-27