BTMOB RAT is a commodity Android remote access trojan sold through a Malware-as-a-Service model and used for device takeover, surveillance, credential theft, and financial fraud. Its capabilities include real-time remote control, keylogging, screen monitoring and recording, camera access, GPS tracking, audio recording, file management, command execution, and data exfiltration. It abuses Android Accessibility Services and supports WebView-based credential capture and WebSocket-based remote control, enabling operators to monitor users and interact with compromised devices.
BTMOB RAT targets banking and cryptocurrency users, with activity documented in Brazil, Argentina, Spain, Portugal, and Mexico, and broader campaigns spanning Europe, Latin America, and Asia. Distribution includes phishing websites and fraudulent application-download pages delivering malicious Android packages. MiningDropper and newer BeatBanker variants install BTMOB RAT as a payload; these delivery chains use staged loading and deceptive Google Play update interfaces. BeatBanker deployments also provide persistent access while retaining a separate cryptocurrency-mining component.
BTMOB RAT belongs to the Android malware ecosystem associated with SpySolr, CraxsRAT, and CypherRAT. It is promoted through Telegram-based sales channels, and leaked source code has circulated on underground forums.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Recent iterations of the campaign have been found to drop BTMOB RAT instead of the banking module."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Cyble said that final payload can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real time remote control, screen monitoring, file handling, audio recording, and command execution.
"The initial APK file is packed... libludwwiuh.so... decrypt another ELF..." and "names are encrypted... using XOR (stack strings technique)"
Il récupère des données de l'interface utilisateur de l'appareil, ce qui inclut des informations sensibles sur l'écran, telles que des identifiants de connexion, des messages, ou des informations bancaires.
Cyble said that final payload can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real time remote control, screen monitoring, file handling, audio recording, and command execution.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android remote access trojan listed among malware families abusing accessibility services. It was documented targeting banking customers in Brazil, Argentina, Spain, Portugal, and Mexico during 2025 and 2026.
Android malware/RAT targeting banking and cryptocurrency users in Brazil, distributed via MaaS-style models and featuring self-propagation and evasion capabilities.
Android RAT/banking malware family targeting banking and cryptocurrency users in Brazil, distributed via MaaS-style models and featuring self-propagation and evasion.
Mentioned only as another malware/tool distributed by the same Telegram channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.