BTMOB Android RAT malware-as-a-service activity
Malware Activity
Summary
Hide ▲
Show ▼
The BTMOB Android RAT kept being sold and updated as a malware-as-a-service package across 2025-2026, extending its reach and increasing the risk of information theft and remote control on Android phones. The operation also splintered into a broader underground market with resellers, source-code sellers, and independent administrators. Official releases continued while cheaper lookalike offers and Telegram sales campaigns pushed access, infrastructure, and code.
Related Happenings
BTMOB's underground market fragments into resellers and source-code sellers
Threat Actor Meta
H score20
First: 03.08.2026 17:45
Last: 03.08.2026 17:45
Sources 1
How related:
Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.
About this happening:
BTMOB's underground market has fragmented into resellers, source-code sellers, and independent administrators, weakening control over the Android RAT ecosystem...
BTMOB's underground market fragments into resellers and source-code sellers
Threat Actor MetaHow related: Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.
About this happening: BTMOB's underground market has fragmented into resellers, source-code sellers, and independent administrators, weakening control over the Android RAT ecosystem...
BTMOB Android MaaS platform expands low-code phishing payload production
Threat Actor Meta
H score21
First: 29.05.2026 00:10
Last: 29.05.2026 00:10
Sources 1
About this happening:
BTMOB has been exposed as a malware-as-a-service Android trojan with a builder interface, making it easier for cybercriminals to mass-produce tailored phishing payload...
BTMOB Android MaaS platform expands low-code phishing payload production
Threat Actor MetaAbout this happening: BTMOB has been exposed as a malware-as-a-service Android trojan with a builder interface, making it easier for cybercriminals to mass-produce tailored phishing payload...
BTMOB Android RAT no-code builder malware activity
Malware Activity
H score28
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
Latest development: 29.05.2026 00:10
BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.
Timeline
-
03.08.2026 17:45 2 articles · 1h ago
BTMOB Android RAT malware-as-a-service activity
Initial DisclosureIn early 2025, the official BTMOB channel sold V2 access and private infrastructure while handling server issues and heavy traffic. That early phase showed the service operating as a centrally managed malware business with shared infrastructure and customer support.
Show sources
- Inside the Underground Business of BTMOB RAT — www.bleepingcomputer.com — 03.08.2026 17:45
- Inside the Underground Business of BTMOB RAT — www.bleepingcomputer.com — 03.08.2026 17:45