0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

BTMOB Android Remote Access Trojan Distributed via No-Code Builder Tool (welivesecurity.com)

· 62d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • BTMOB is sold with a no-code APK builder enabling rapid payload generation.
  • Delivered via phishing sites and fake app stores, abusing Accessibility Services.
  • Initially detected in Brazil, marketed globally via Telegram and social media.

"ESET researchers identified BTMOB, an Android RAT evolved from SpySolr, sold as a malware-as-a-service with a no-code APK builder. Delivered through phishing sites and fake app stores, it abuses Accessibility Services to seize device control. The malware targets Brazil initially but is marketed globally via Telegram and social media. A $5,000 lifetime license enables rapid payload generation. ESET detects it as MSIL/BtmobRat and variants."

Discussion Matrix

0 segments

no comments yet.