BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
BTMOB Android RAT (TL-2026-0600), also tracked as BTMOB RAT, is a high-severity malware campaign, first published 2026-05-27 and last reviewed 2026-08-04. It is attributed to BTMOB MaaS operator with low confidence, affects Google Android, maps to 35 MITRE ATT&CK techniques (T1409, T1414, T1417), and is covered by 9 detection rules and 49 indicators of compromise.
Key facts for TL-2026-0600
- Threat ID
- TL-2026-0600
- Also known as
- BTMOB RAT, BTMOB v2.5, SpySolr (predecessor family)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-27
- Last reviewed
- 2026-08-04
- Attribution
- BTMOB MaaS operator
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial, consumer, government, telecommunications, cryptocurrency
- Target regions
- Brazil, Argentina, Latin America
- Detection rules
- 9
- Indicators of compromise
- 49
- Updates
- 2026-08-04
Malware and tooling in BTMOB Android RAT
Malware and tooling: Android/Spy.Agent.EED, Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, Android/Spy.Spysolr.A, BTMOB, MSIL/BtmobRat, SpySolr, BTMOB APK Builder, BTMOB MaaS APK builder + Telegram operator
BTMOB is an Android remote access trojan that evolved from the SpySolr malware family first publicly documented by Cyble in February 2025. It is sold as malware-as-a-service ($5,000 lifetime license plus a monthly support fee) through a Telegram-fronted operator with X and Instagram promotion, and ships with an APK builder interface that lets non-developer affiliates generate region-tailored payloads. Once installed via fake app stores fronted by streaming-service or crypto-mining lures, BTMOB abuses Android Accessibility Services to elevate permissions, capture screenshots, record device activity, exfiltrate sensitive data, and grant operators full remote control of the device. Active campaigns have been observed in Brazil and Argentina impersonating tax and customs authorities.
How BTMOB Android RAT works
BTMOB is a commodity Android remote access trojan (RAT) and information-stealer documented by ESET researcher Daniel Cunha Barbosa on 26 May 2026. ESET attributes BTMOB as a direct evolution of the SpySolr Android malware first profiled in a Cyble report in February 2025, where roughly 15 v2.5 samples were observed within approximately two weeks of late January 2025. The family is operated under a malware-as-a-service (MaaS) model: a public-facing promotional page advertises the tool on the open web and funnels prospective buyers to a Telegram operator, while a sales pipeline extending across X (Twitter) and Instagram peddles the kit to less sophisticated adversaries. The reported pricing is a $5,000 lifetime license plus a recurring monthly support fee — a price point that ESET assesses as low relative to the fraud returns a successful operation can generate and that materially lowers the barrier to entry.
The BTMOB kit ships with an APK builder interface that allows non-developer affiliates to repackage the implant with customised phishing lures, branding, and language so the dropper impersonates the brand or government agency most likely to lure victims in any given country. Researchers Johnk3r and Merl (cited by ESET) recently observed campaigns spreading BTMOB while impersonating Argentina's national tax and customs authorities, and additional activity has been seen in Brazil. Because variants can be regenerated quickly by affiliates, defenders should expect rapid payload turnover rather than a stable IOC set.
Infection begins with social engineering. Operators direct targets to phishing websites that pose as legitimate streaming services, cryptocurrency-mining platforms, or other familiar online services. Victims are then funnelled to fake app stores that imitate the visual identity of legitimate repositories such as Google Play and instructed to install a malicious APK side-load. Once the APK is installed, BTMOB requests broad permissions and — critically — abuses the Android Accessibility Services framework. By coercing the victim into granting the Accessibility permission, the implant gains the ability to read screen content, simulate user input, auto-approve subsequent permission prompts, and overlay deceptive screens, effectively granting itself further system access without additional user interaction.
Post-installation, BTMOB's capabilities include screen capture and screen recording, audio capture, harvesting of notifications and clipboard contents, keystroke and on-screen input capture via Accessibility, location tracking, exfiltration of credentials and stored application data, and full remote control of the device — allowing the operator to interact with banking, email, and messaging applications in real time. ESET products detect the Windows-side builder/operator tooling as MSIL/BtmobRat, while the Android payloads trigger detections such as Android/Spy.Agent.EED, Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, Android/Spy.Spysolr.A, Android/TrojanDropper.Agent.NES, Android/TrojanDropper.Agent.NDK, Android/TrojanDropper.Agent.NBO, Android/Spy.Agent.EUG, Android/Spy.Agent.EWN, Android/Spy.Agent.FFE, Android/Spy.Agent.FFL, Android/Spy.Agent.FFM, Android/Spy.Agent.FEE, Android/Spy.Agent.ELM, and Android/Agent.FQK.
A secondary-market risk amplifies the threat surface. In January 2026, a dark web forum claimed to offer BTMOB-related files for free download; the forum has since gone offline and ESET could not recover the payload(s), but the episode is consistent with the recurring pattern of commercial Android malware leaking out of paid distribution and into secondary resale, barter, and sharing inside closed groups. Defenders should treat the IOC list as a triage starting point rather than a definitive boundary — infrastructure churn is expected, but specific patterns (the arbsniper.com C2 domain, the 191.96.78.0/24 and 191.96.79.0/24 hosting ranges, and SHA256 hashes of leaked builder outputs) often recur across affiliates.
MITRE ATT&CK techniques used in TL-2026-0600
Collection
T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1513 Screen Capture; T1532 Archive Collected Data; T1636 Protected User Data
collection
T1414 Clipboard Data; T1417 Input Capture; T1517 Access Notifications
Discovery
T1418 Software Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery
command-and-control
T1437 Application Layer Protocol; T1481 Web Service; T1521 Encrypted Channel
initial-access
T1456 Drive-By Compromise; T1474 Supply Chain Compromise; T1660 Phishing
defense-evasion
T1516 Input Injection; T1628 Hide Artifacts; T1632 Subvert Trust Controls; T1655 Masquerading
Persistence
T1541 Foreground Persistence; T1624 Event Triggered Execution
Execution
Impact
T1582 SMS Control; T1641 Data Manipulation
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
privilege-escalation
T1626 Abuse Elevation Control Mechanism
Exfiltration
Affected products and versions in BTMOB Android RAT
- Google — Android
Vulnerable versions: 7.0; 8.0; 9.0; 10; 11; 12; 13; 14; 15
Remediation for BTMOB Android RAT
Immediate actions
- Block the C2 domain arbsniper.com and the 21 known IP indicators at perimeter DNS, proxy, and firewall enforcement points
- Sweep mobile device management (MDM) and EDR telemetry for any of the 35 SHA256 hashes; isolate any device that has installed a matching APK
- Block side-loading of unknown APKs via MDM policy (disallow installation from unknown sources) on all corporate Android fleets
- Hunt for newly-granted Accessibility Services permissions on managed Android devices in the last 90 days and review the granting apps
- Push an out-of-band user advisory warning against installing apps from links delivered by SMS, messaging apps, or advertisements impersonating tax/customs authorities, streaming services, or crypto-mining platforms
Workarounds
- On Android 11+, leverage scoped Accessibility restrictions and Restricted Setting prompts that block sideloaded apps from using Accessibility Services by default
- Configure Google Play Protect to be enabled on all managed Android devices and verify it has not been disabled by the user or a sideloaded app
Longer-term hardening
- Mandate installation of mobile apps exclusively from official repositories (Google Play, vetted enterprise MDM stores) via MDM compliance policy
- Deploy a mobile threat defence (MTD) or mobile EDR solution capable of detecting Accessibility Service abuse, overlay attacks, and known Android RAT families
- Treat corporate mobile devices with the same monitoring rigor as workstations: collect process, network, and permission-grant telemetry where the platform allows
- Train users on the social-engineering lures used by BTMOB affiliates (streaming/crypto/government impersonation) and the risk of granting Accessibility Services to non-assistive apps
- Subscribe to a feed that tracks Android Accessibility-abusing banking trojans (SpyNote, Hydra, Hook, BRATA, TgToxic, Crocodilus, BTMOB) and refresh IOC blocklists on a recurring cadence
Weaknesses (CWE) in BTMOB Android RAT
CWE-1330, CWE-829, CWE-749
Timeline of BTMOB Android RAT
- Cyble researchers observe the first wave of SpySolr v2.5 samples — approximately 15 samples surface within roughly two weeks, foreshadowing the BTMOB lineage.
- Cyble publishes the initial public analysis of SpySolr v2.5, the direct predecessor of BTMOB, documenting MaaS distribution and Accessibility-Service abuse.
- Operators rebrand and re-tool SpySolr under the BTMOB name, expanding the affiliate program through a Telegram-fronted operator and X/Instagram promotion.
- A dark web forum claims to offer BTMOB builder files for free download, raising the risk of secondary-market reuse; the forum subsequently goes offline before payloads can be recovered.
- Researchers Johnk3r and Merl document BTMOB affiliate campaigns impersonating Argentina's tax and customs authorities, distributed via fake app stores.
- Brazilian-language BTMOB lures observed in the wild, impersonating local streaming services and crypto-mining brands to drive APK side-loading.
- ESET (Daniel Cunha Barbosa) publishes the full BTMOB analysis on WeLiveSecurity, including IOCs, MaaS economics, and the SpySolr lineage attribution.
- Threadlinqs Intelligence publishes TL-2026-0600 covering BTMOB with full MITRE Mobile mapping, IOC normalisation, and detection coverage.
- As of 2026-05-29, BTMOB remains an active Android RAT MaaS: ESET, The Hacker News, Dark Reading and a Rescana "active exploitation alert" all report ongoing Brazil/LatAm/EU campaigns with no takedown. The operator (EVLF/@craxso) is still openly selling it via Telegram/X, shipped v4.5.5 in May 2026, and leaked builds now circulate on forums.
Update history for TL-2026-0600
- 2026-08-04 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), families: BTMOB, 1 community-related indicator(s).
Sources cited for BTMOB Android RAT
- BTMOB: A stealthy RAT burrowing deep into Android devices
- SpySolr: Cyble analysis of v2.5 Android RAT samples (Feb 2025)
- MITRE ATT&CK Mobile: T1660 Phishing
- MITRE ATT&CK Mobile: T1626 Abuse Elevation Control Mechanism
- MITRE ATT&CK Mobile: T1513 Screen Capture
- MITRE ATT&CK Mobile: T1655 Masquerading
- Android Developers: Accessibility Service security guidance
- Germán Fernández Bacian — BTMOB Argentina tax impersonation campaign
- @Merlax_ — Fake app store imagery linked to BTMOB
Threats related to BTMOB Android RAT
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users in France, Italy, and Austria
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader
- Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking and Crypto Apps
Detection coverage for TL-2026-0600
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0600 across Splunk SPL, Microsoft KQL and Sigma, covering 49 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0600
10 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.