Find notable cyber news and cases, enriched with sources, timelines, and signals.

BTMOB's underground market fragments into resellers and source-code sellers

Threat Actor Meta
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

BTMOB's underground market has fragmented into resellers, source-code sellers, and independent administrators, weakening control over the Android RAT ecosystem. Across 2025-2026, the same brand was used for competing offers of access, private infrastructure, and source code, creating uncertainty over who was behind each sale. The shift expands the market for cheaper copies and lookalike versions while making support and authenticity harder to verify. It turns BTMOB from a single malware service into a contested criminal software marketplace.

Related Happenings

BTMOB Android RAT malware-as-a-service activity

Malware Activity
H score27 First: 03.08.2026 17:45 Last: 03.08.2026 17:45 Sources 1

How related: BTMOB is primarily an Android remote access trojan where its malicious application is installed on a victim’s phone to steal information and provide remote control.

About this happening: The BTMOB Android RAT kept being sold and updated as a malware-as-a-service package across 2025-2026, extending its reach and increasing the risk of information...

Timeline

  1. 03.08.2026 17:45 2 articles · 1h ago

    BTMOB's underground market fragments into resellers and source-code sellers

    Initial Disclosure

    In early 2025, the operation still looked like a single malware business with one main channel selling access and infrastructure. Later in the year, source-code sales and independent operators began pulling the brand apart.

    Show sources