BTMOB is an Android remote access trojan (RAT) and malware-as-a-service platform, first identified in 2025 and derived from the SpySolr family. It combines a malicious Android payload with builder, dropper, command-and-control, and operator-panel components that enable purchasers to create localized campaigns with limited technical expertise. BTMOB is primarily distributed through phishing and fraudulent websites or counterfeit app-store pages impersonating services such as streaming platforms, cryptocurrency services, banking-related applications, and government entities. Victims are induced to sideload malicious Android applications.
Following installation, BTMOB abuses Android Accessibility Services to obtain broad permissions and facilitate remote operation of the compromised device. Confirmed capabilities include remote device control, screen capture and activity monitoring, keystroke logging, credential theft through overlays or HTML injections, message interception or reading, collection of device and application information, and exfiltration of data. It can maintain access through its elevated permissions and command-and-control communications. Campaigns have targeted mobile users in Latin America, including Brazil and Argentina, while Ukrainian authorities have associated BTMOB distribution through fake air-raid-alert and fuel-discount application sites with UAC-0263. BTMOB has also been distributed through fraudulent IPTV and World Cup streaming applications. Its commercial and increasingly fragmented ecosystem includes resellers and independently operated variants, complicating attribution and tracking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC-0263 has used decoy websites offering purported apps for air raid alerts, fuel discounts and other services. Its malware, known as BTMOB, gives hackers remote access to infected devices and allows them to steal information.
The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands in order to divert them to fraudulent application repositories containing malicious Android applications.
BTMOB... enables operators to remotely monitor, manipulate, and control compromised devices... The BTMOB establishes communication with attacker-controlled command-and-control infrastructure... allowing the operator to remotely manage the compromised device and maintain persistent access
BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.
“DarkSword can be used to gather sensitive data such as login credentials, messages, contacts, and call histories” and CamelSpy collects “contacts, call logs, and stored images.”
BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.
WebSocket URL pattern ws://<host>:8080/con BTMob WebSocket command-and-control connection
HTTP POST to /yaarsa/private/yarsap_*.php ... /yaarsa/private/createacc.php ... /yaarsa/user/loginbt.php ... /yaarsa/index.php | ws://<host>:8080/con 426 Upgrade Required /yaarsa/server/websocket-server.js
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile remote-access malware that provides control of compromised devices and steals information; it is distributed through lure websites promoting purported air-raid alerts, fuel discounts, and other services.
Android remote-access malware distributed via decoy app websites. It provides attackers remote access to compromised devices and enables information theft.
Android remote-access trojan advertised as targeting Android 4 through 17. Claimed capabilities include remote/silent screen control, banking and cryptocurrency credential theft via overlays/injections, keylogging, browser-password theft, location and contact collection, application management/cloning, call and SMS interception or blocking, persistence/anti-kill functions, hidden application icons, and DDoS functionality.
Android remote access trojan offered as a malware-as-a-service platform. It includes a malicious app, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools, with options for private infrastructure, customized builds, and technical support.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.