The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
BTMOB
BTMOB is an Android remote access trojan derived from the SpySolr malware family and operated as a malware-as-a-service offering.
Profile source: Mallory opens in a new tabBTMOB
Family profile
BTMOB is an Android remote access trojan derived from the SpySolr malware family and operated as a malware-as-a-service offering. First observed in 2025, it is designed to lower the barrier to entry for financially motivated operators by pairing a RAT payload with builder tooling that allows customized malicious Android applications and localized social-engineering lures to be created without significant technical skill. The ecosystem around BTMOB has expanded beyond a single centrally controlled service into a fragmented market that includes resellers, source-code vendors, and independently operated infrastructure.
BTMOB is primarily distributed through phishing-driven infection chains and fraudulent Android applications masquerading as legitimate services. Observed lures have impersonated streaming and IPTV platforms, cryptocurrency-related services, app stores, and government or tax agencies, including campaigns in Latin America and World Cup-themed streaming offers. Victims are typically redirected to counterfeit app-store pages or other fake distribution points and persuaded to sideload a malicious APK.
Once installed, BTMOB abuses Android Accessibility Services to obtain elevated privileges and silently grant itself additional permissions. It then establishes command-and-control connectivity and enables persistent remote access to the compromised device. Reported capabilities include remote device control, command execution, message access, victim information collection, screenshot and screen-recording capture, keylogging, credential theft through HTML injection or overlay-style phishing, device unlocking, camera access, GPS tracking, and broader data exfiltration. Some reporting also describes its use as a module in other Android malware campaigns, where it replaces or supplements banking-trojan functionality to enable full-device compromise.
BTMOB has been associated with financially motivated activity rather than a single exclusive threat actor. It has been marketed openly through web and social channels and sold with licensing and support options, while leaked or resold components have raised the prospect of wider criminal adoption. Its combination of phishing-led delivery, accessibility abuse, rapid variant generation, and broad surveillance and takeover features makes it a significant Android threat, particularly for users exposed to sideloaded applications and fake mobile-service lures.
Capabilities
- Credential Theft
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
Reported operators
Threat actors
2 named in public reportingBesides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
MITRE ATT&CK
BTMOB in ATT&CK
19 distinct techniquesTechniques
19 techniquesReporting
Research mentioning BTMOB
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Kaspersky reported that Android attacks involving malware, adware, and unwanted software fell to 1,996,823 in Q2 2026 from 2,676,328 in the previous quarter, but banking malware remained the leading threat. Trojan-Banker detections accounted for 30.77% of malicious applications, and researchers identified more than 304,000 malicious installation packages, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages. The report also noted that some banking Trojans were reclassified as droppers as attackers increasingly packed payloads, contributing to growth in Trojan-Dropper detections. The quarter’s most notable campaigns included malicious loaders distributed through Google Play. Researchers said a trojanized PDF reader was used to deliver the Anatsa banking Trojan, while the Cleanova app relied on SDK telemetry to selectively activate malicious functionality and evade app store review. Kaspersky also said Triada variants remained prominent, Mamont banking Trojan variants rose sharply and appear to be under active development, and attacks tied to some pre-installed Trojans declined, likely because vendors patched affected firmware.
IT threat evolution in Q2 2026. Mobile statistics - Malware News - Malware Analysis, News and Indicators
Q2 2026 Android threat landscape | Securelist
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform. The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.