The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
BTMOB
BTMOB is an Android remote access trojan (RAT) and malware-as-a-service platform, first identified in early 2025 and derived from the SpySolr family.
Profile source: Mallory opens in a new tabBTMOB
Family profile
BTMOB is an Android remote access trojan (RAT) and malware-as-a-service platform, first identified in early 2025 and derived from the SpySolr family. It provides a no-code APK builder, payload-generation tooling, operator control panels, and supporting server infrastructure, enabling buyers to create localized malicious applications and social-engineering campaigns with limited technical expertise. The ecosystem has evolved from a more centralized service into a fragmented market of resellers, independent operators, and purported source-code variants.
BTMOB is commonly delivered through phishing campaigns that lead victims to counterfeit websites and fake application-store pages impersonating streaming services, cryptocurrency services, government agencies, financial services, and other trusted brands. Victims are induced to sideload a malicious Android application and enable Android Accessibility Services. The malware abuses accessibility privileges to obtain additional permissions and facilitate device control.
On compromised devices, BTMOB supports remote administration and surveillance, including screen capture or recording, keylogging, message and notification access, camera access, device-information collection, command execution, and sensitive-data theft. It can use HTML injection or overlay-style mechanisms to capture credentials and payment-related data, and has been reported to capture PINs in some variants. BTMOB has been observed in campaigns affecting Brazil and other Latin American locations, including Argentina-themed government lures, but its customizable builder and phishing framework permit targeting across regions. Campaigns have also used IPTV and streaming-themed applications as lures.
Capabilities
- Credential Theft
- Exfiltration
- Initial Access
- Keylogging
- Persistence
- Post Exploitation
Reported operators
Threat actors
2 named in public reportingBesides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
MITRE ATT&CK
BTMOB in ATT&CK
24 distinct techniquesTechniques
24 techniquesReporting
Research mentioning BTMOB
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
Researchers reported that BTMob is operating as an Android banking malware and fraud-as-a-service platform that lets multiple criminal actors create branded malicious apps and run large-scale device-takeover campaigns. Analysis of leaked source packages and exposed infrastructure linked the operation to roughly 1,400 live servers, including command-and-control nodes, an automated APK-building ecosystem, and backend components used to manage victim infections and operator access. The platform is being spread through fake apps, cloned download pages, and social-engineering lures, including WhatsApp messages and phone calls in Brazil that pressure victims to sideload APKs and grant dangerous permissions. Investigators tied the activity to infrastructure using /yaarsa/ PHP backend paths, HTTP and WebSocket endpoints, a control panel on port 3000 identified by the string "painel de controle elite", and payloads including lnat-tv-pro.apk, BTMob.exe, SolrStarter.exe, and SolrWorker.exe, while also linking the operation to the earlier CraxsRAT and SpySolr malware families.
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers | Cryptika Cybersecurity
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Kaspersky reported that Android attacks involving malware, adware, and unwanted software fell to 1,996,823 in Q2 2026 from 2,676,328 in the previous quarter, but banking malware remained the leading threat. Trojan-Banker detections accounted for 30.77% of malicious applications, and researchers identified more than 304,000 malicious installation packages, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages. The report also noted that some banking Trojans were reclassified as droppers as attackers increasingly packed payloads, contributing to growth in Trojan-Dropper detections. The quarter’s most notable campaigns included malicious loaders distributed through Google Play. Researchers said a trojanized PDF reader was used to deliver the Anatsa banking Trojan, while the Cleanova app relied on SDK telemetry to selectively activate malicious functionality and evade app store review. Kaspersky also said Triada variants remained prominent, Mamont banking Trojan variants rose sharply and appear to be under active development, and attacks tied to some pre-installed Trojans declined, likely because vendors patched affected firmware.
IT threat evolution in Q2 2026. Mobile statistics - Malware News - Malware Analysis, News and Indicators
Q2 2026 Android threat landscape | Securelist
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform. The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.