BTMOB is an Android remote access trojan derived from the SpySolr malware family and operated as a malware-as-a-service offering. First observed in 2025, it is designed to lower the barrier to entry for financially motivated operators by pairing a RAT payload with builder tooling that allows customized malicious Android applications and localized social-engineering lures to be created without significant technical skill. The ecosystem around BTMOB has expanded beyond a single centrally controlled service into a fragmented market that includes resellers, source-code vendors, and independently operated infrastructure.
BTMOB is primarily distributed through phishing-driven infection chains and fraudulent Android applications masquerading as legitimate services. Observed lures have impersonated streaming and IPTV platforms, cryptocurrency-related services, app stores, and government or tax agencies, including campaigns in Latin America and World Cup-themed streaming offers. Victims are typically redirected to counterfeit app-store pages or other fake distribution points and persuaded to sideload a malicious APK.
Once installed, BTMOB abuses Android Accessibility Services to obtain elevated privileges and silently grant itself additional permissions. It then establishes command-and-control connectivity and enables persistent remote access to the compromised device. Reported capabilities include remote device control, command execution, message access, victim information collection, screenshot and screen-recording capture, keylogging, credential theft through HTML injection or overlay-style phishing, device unlocking, camera access, GPS tracking, and broader data exfiltration. Some reporting also describes its use as a module in other Android malware campaigns, where it replaces or supplements banking-trojan functionality to enable full-device compromise.
BTMOB has been associated with financially motivated activity rather than a single exclusive threat actor. It has been marketed openly through web and social channels and sold with licensing and support options, while leaked or resold components have raised the prospect of wider criminal adoption. Its combination of phishing-led delivery, accessibility abuse, rapid variant generation, and broad surveillance and takeover features makes it a significant Android threat, particularly for users exposed to sideloaded applications and fake mobile-service lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control.
Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands in order to divert them to fraudulent application repositories containing malicious Android applications.
Malware primarily distributes itself through phishing campaigns and fraudulent applications masquerading as legitimate online services... In order to achieve operational success, BTMOB will continue to rely heavily on phishing-driven infection chains designed to maximize the trust of the user base.
BTMOB... enables operators to remotely monitor, manipulate, and control compromised devices... The BTMOB establishes communication with attacker-controlled command-and-control infrastructure... allowing the operator to remotely manage the compromised device and maintain persistent access
The threat actors often redirect targets to counterfeit websites masquerading as streaming platforms, cryptocurrency services, or other widely recognised online brands... Additionally, attacks have been observed that are tailored to align with local institutions and government entities, including operations impersonating Argentine tax and public sector agencies as lures.
These include the ability to exfiltrate a range of sensitive data, capture screenshots, record activity on the device, and ultimately take remote control of it.
BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.
BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes
The BTMOB establishes communication with attacker-controlled command-and-control infrastructure with these privileges, allowing the operator to remotely manage the compromised device and maintain persistent access
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware family listed among the most frequently detected mobile malware in Q2 2026.
Android spyware/trojan-spy family newly appearing among top mobile malware detections for the quarter.
Android spyware family newly appearing among top detected mobile malware in the reporting period.
BTMOB is an Android remote access trojan sold as a malware-as-a-service. It was initially offered as a full package including droppers, a payload builder, an operator panel, and server infrastructure, and has since fragmented into an ecosystem of resellers, source-code vendors, independent server operators, and custom variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.