BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse — Threadlinqs Intelligence
As of 2026-05-30, BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse is a high-severity malware threat attributed to BTMOB MaaS operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 49 indicators of compromise.
Threat ID: TL-2026-0600 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: BTMOB MaaS operator · FINANCIAL
BTMOB is an Android remote access trojan that evolved from the SpySolr malware family first publicly documented by Cyble in February 2025. It is sold as malware-as-a-service ($5,000 lifetime license
BTMOB is a commodity Android remote access trojan (RAT) and information-stealer documented by ESET researcher Daniel Cunha Barbosa on 26 May 2026. ESET attributes BTMOB as a direct evolution of the SpySolr Android malware first profiled in a Cyble report in February 2025, where roughly 15 v2.5 samples were observed within approximately two weeks of late January 2025. The family is operated under a malware-as-a-service (MaaS) model: a public-facing promotional page advertises the tool on the open web and funnels prospective buyers to a Telegram operator, while a sales pipeline extending across X (Twitter) and Instagram peddles the kit to less sophisticated adversaries. The reported pricing is a $5,000 lifetime license plus a recurring monthly support fee — a price point that ESET assesses as low relative to the fraud returns a successful operation can generate and that materially lowers the barrier to entry.
The BTMOB kit ships with an APK builder interface that allows non-developer affiliates to repackage the implant with customised phishing lures, branding, and language so the dropper impersonates the brand or government agency most likely to lure victims in any given country. Researchers Johnk3r and Merl (cited by ESET) recently observed campaigns spreading BTMOB while impersonating Argentina's national tax and customs authorities, and additional activity has been seen in Brazil. Because variants can be regenerated quickly by affiliates, defenders should expect rapid payload turnover rather than a stable IOC set.
Infection begins with social engineering. Operators direct targets to phishing websites that pose as legitimate streaming services, cryptocurrency-mining platforms, or other familiar online services. Victims are then funnelled to fake app stores that imitate the visual identity of legitimate repositories such as Google Play and instructed to install a malicious APK side-load. Once the APK is installed, BTMOB requests broad permissions and — critically — abuses the Android Accessibility Services framework. By coercing the victim into granting the Accessibility permission, the implant gains the ability to read screen content, simulate user input, auto-approve subsequent permission prompts, and overlay deceptive screens, effectively granting itself further system access without additional user interaction.
Post-installation, BTMOB's capabilities include screen capture and screen recording, audio capture, harvesting of notifications and clipboard contents, keystroke and on-screen input capture via Accessibility, location tracking, exfiltration of credentials and stored application data, and full remote control of the device — allowing the operator to interact with banking, email, and messaging applications in real time. ESET products detect the Windows-side builder/operator tooling as MSIL/BtmobRat, while the Android payloads trigger detections such as Android/Spy.Agent.EED, Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, Android/Spy.Spysolr.A, Android/TrojanDropper.Agent.NES, Android/TrojanDropper.Agent.NDK, Android/TrojanDropper.Agent.NBO, Android/Spy.Agent.EUG, Android/Spy.Agent.EWN, Android/Spy.Agent.FFE, Android/Spy.Agent.FFL, Android/Spy.Agent.FFM, Android/Spy.Agent.FEE, Android/Spy.Agent.ELM, and Android/Agent.FQK.
A secondary-market risk amplifies the threat surface. In January 2026, a dark web forum claimed to offer BTMOB-related files for free download; the forum has since gone offline and ESET could not recover the payload(s), but the episode is consistent with the recurring pattern of commercial Android malware leaking out of paid distribution and into secondary resale, barter, and sharing inside closed groups. Defenders should treat the IOC list as a triage starting point rather than a definitive boundary — infrastructure churn is expected, but specific patterns (the arbsniper.com C2 domain, the 191.96.78.0/24 and 191.96.79.0/24 hosting ranges, and SHA256 hashes of leaked builder outputs) often recur acro
Weaknesses (CWE)
CWE-1330, CWE-829, CWE-749
Target sectors: financial, consumer, government, telecommunications, cryptocurrency
Target regions: Brazil, Argentina, Latin America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 49 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1587, T1608, T1585, T1660, T1456, T1474, T1575, T1541