Find notable cyber news and cases, enriched with sources, timelines, and signals.

BTMOB Android RAT malware-as-a-service activity

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The BTMOB Android RAT kept being sold and updated as a malware-as-a-service package across 2025-2026, extending its reach and increasing the risk of information theft and remote control on Android phones. The operation also splintered into a broader underground market with resellers, source-code sellers, and independent administrators. Official releases continued while cheaper lookalike offers and Telegram sales campaigns pushed access, infrastructure, and code.

Related Happenings

BTMOB's underground market fragments into resellers and source-code sellers

Threat Actor Meta
H score20 First: 03.08.2026 17:45 Last: 03.08.2026 17:45 Sources 1

How related: Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.

About this happening: BTMOB's underground market has fragmented into resellers, source-code sellers, and independent administrators, weakening control over the Android RAT ecosystem...

BTMOB Android MaaS platform expands low-code phishing payload production

Threat Actor Meta
H score21 First: 29.05.2026 00:10 Last: 29.05.2026 00:10 Sources 1

About this happening: BTMOB has been exposed as a malware-as-a-service Android trojan with a builder interface, making it easier for cybercriminals to mass-produce tailored phishing payload...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

Timeline

  1. 03.08.2026 17:45 2 articles · 1h ago

    BTMOB Android RAT malware-as-a-service activity

    Initial Disclosure

    In early 2025, the official BTMOB channel sold V2 access and private infrastructure while handling server issues and heavy traffic. That early phase showed the service operating as a centrally managed malware business with shared infrastructure and customer support.

    Show sources