BTMOB RAT is an Android remote access trojan used in financially motivated campaigns targeting banking and cryptocurrency users, with notable activity affecting Brazil and broader regional targets in Europe, Latin America, and Asia. It has been described as a full-featured Android malware family and commodity MaaS offering that provides operators with extensive control over compromised devices and supports fraud operations through credential capture and device takeover. Reporting has linked it to the broader CraxsRAT, CypherRAT, and SpySolr ecosystem, and some analyses identify it as a variant or evolution of SpySolr.
BTMOB RAT supports real-time remote control of infected Android devices and surveillance-oriented functions including keylogging, screen monitoring or recording, camera access, GPS or location tracking, audio capture, file handling, and command execution. It has also been associated with credential harvesting, browser password theft, Accessibility Service abuse, and WebView- or overlay-based theft mechanisms that facilitate banking and cryptocurrency fraud. Recent campaigns and operator advertisements additionally indicate persistence features, icon hiding, anti-analysis or evasion behavior, and the ability to bypass some mobile security and banking-app protections.
Distribution has been observed through phishing sites, fake app download pages, fraudulent pages impersonating trusted services, and malicious Android applications, including apps promoted through counterfeit Google Play-style pages. Some reporting also states that malicious apps were available through Google Play Store listings. BTMOB RAT has been delivered directly and via multi-stage Android delivery frameworks such as MiningDropper, as well as by newer BeatBanker campaign variants that replaced an earlier banking module with BTMOB RAT. Underground distribution and operator support have also been tied to Telegram-based channels, consistent with a MaaS commercialization model.
The malware is primarily associated with financial theft and post-compromise remote administration on Android devices. Targeting has focused on mobile users whose devices can be leveraged for banking fraud, cryptocurrency theft, credential theft, and broader surveillance of victim activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Recent iterations of the campaign have been found to drop BTMOB RAT instead of the banking module."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Cyble said that final payload can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real time remote control, screen monitoring, file handling, audio recording, and command execution.
"The initial APK file is packed... libludwwiuh.so... decrypt another ELF..." and "names are encrypted... using XOR (stack strings technique)"
Il récupère des données de l'interface utilisateur de l'appareil, ce qui inclut des informations sensibles sur l'écran, telles que des identifiants de connexion, des messages, ou des informations bancaires.
Cyble said that final payload can steal credentials through WebView injections, log keystrokes, exfiltrate data, abuse Accessibility Services, and support real time remote control, screen monitoring, file handling, audio recording, and command execution.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware/RAT targeting banking and cryptocurrency users in Brazil, distributed via MaaS-style models and featuring self-propagation and evasion capabilities.
Android RAT/banking malware family targeting banking and cryptocurrency users in Brazil, distributed via MaaS-style models and featuring self-propagation and evasion.
Mentioned only as another malware/tool distributed by the same Telegram channel.
Named as another RAT distributed by the same Telegram channel, but not materially analyzed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.