0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

BTMOB Android RAT Distributed via No-Code Builder Tooling (infosecurity-magazine.com)

· 63d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • BTMOB is an Android RAT sold as a service with a no-code builder for fast payload customization.
  • The malware abuses Android Accessibility Services for privilege escalation and full device takeover.
  • Campaigns observed targeting Brazil and Argentina, with others likely to follow due to low barrier to entry.

"ESET researchers detail BTMOB, an Android RAT sold as a malware-as-a-service with a no-code APK builder. Buyers can quickly generate custom payloads and phishing lures targeting specific regions, including campaigns spoofing Argentina's tax authorities. The malware abuses Android Accessibility Services for privilege escalation and full device takeover. A $5,000 lifetime license and monthly support fee lowers entry barriers for less skilled criminals. Defenders face rapid payload turnover due to easy kit retooling."

#Android-RAT #MaaS #Phishing campaigns

Discussion Matrix

0 segments

no comments yet.