Threat reportMalwareTL-2026-1841

Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service

highACTIVE

Inside the Underground Business of the BTMOB Android RAT (TL-2026-1841), also tracked as BeatBanker, is a high-severity malware campaign, first published 2026-08-03. It is attributed to EVLF with medium confidence, affects Google Android, maps to 25 MITRE ATT&CK techniques (T1204, T1406, T1414), and is covered by 9 detection rules and 48 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
1EVLF
Detection rules
9SPL · KQL · Sigma
IOCs
48Indicators of compromise

Key facts for TL-2026-1841

Threat ID
TL-2026-1841
Also known as
BeatBanker, SpySolr
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
EVLF
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, cryptocurrency, telecoms
Target regions
brazil, Latin America, argentina, turkey
Detection rules
9
Indicators of compromise
48

Malware and tooling in Inside the Underground Business of the BTMOB Android RAT

Malware and tooling: BTMOB, xmrig, BTMob.exe

How Inside the Underground Business of the BTMOB Android RAT works

BTMOB is a sophisticated Android remote access trojan sold as a malware-as-a-service (MaaS) package enabling full device takeover, credential theft via dynamic HTML injection overlays, live screen streaming, keylogging, SMS/2FA interception, and cryptomining. Originally operated as a centralized service from at least January 2025 (v2.5), the ecosystem fragmented through 2025-2026 into independently managed versions, cheaper reseller copies, and competing sales channels following source code sales (originally $20,000) and operator disputes in mid-2025. Multiple security vendors — Cyble, Palo Alto Networks Unit 42, ESET, Zimperium, Flare, D3Lab, Ostorlab — have published detailed technical analyses documenting its evolution through at least v4.6, with source code and cracked copies circulating in the secondary market, lowering the barrier for threat actors globally.

BTMOB (evolved from the SpySolr malware family) is an Android Remote Access Trojan (RAT) sold as a commercial Malware-as-a-Service platform. The malware is distributed through phishing websites impersonating legitimate services — including SpaceX Starlink, Google Chrome, Avast Antivirus, Roku, Amazon, GB WhatsApp, and Bradesco — with region-tailored lures targeting primarily Latin American users, particularly Brazil.

Upon installation, BTMOB requests Android Accessibility Service permissions (BIND_ACCESSIBILITY_SERVICE) under the guise of device optimization or protection. Once granted, it auto-grants all other permissions, disables Google Play Protect, hides its icon from the launcher, and acquires a WakeLock to prevent device sleep. The malware maintains persistence through BOOT_COMPLETED broadcast receivers and a foreground service with a fake "Update Now" system notification.

The RAT communicates with its C2 infrastructure via persistent WebSocket connections (supplemented by HTTP fallback and Firebase Cloud Messaging) and supports 16+ remote commands: screen streaming and capture via the MediaProjection API (VNC-like live control with sub-actions for screen block, paste, navigation, gesture injection), WebView-based phishing overlay injection targeting banking and cryptocurrency applications, keylogging and clipboard monitoring, SMS/contact/location harvesting, microphone recording, file management (including AES encryption), fake chat window display, device lock/unlock via pattern/PIN/password replay (using dispatchGesture API and Accessibility Service), and an on-device cryptominer (modified XMRig v6.17.0 ARM) for passive revenue generation.

The C2 backend (recovered by D3Lab analysis of leaked source code) is a centralized SaaS platform built on Apache 2.4.52 with PHP 8.1.2, Node.js Express on port 3000, MariaDB, WebSocket services on port 8080, and RDP on port 3389. The codebase is organized under a directory named "yaarsa" with user/ and private/ paths containing dozens of PHP command handlers. Critically, the operator authentication flows through the developer's backend: customers obtain session tokens (with 2FA) and the actual APK compilation occurs remotely on the threat actor's server, meaning the developer retains unrestricted access to every victim managed by every paying customer.

A particularly sophisticated capability documented by Zimperium targets Alipay PINs via transparent overlay injection — the malware monitors the UI for Alipay's PIN pad, overlays transparent views over each numeric button, captures taps via gesture injection, and exfiltrates digits in real-time with context label "Alipay|PIN|<digit>". Ostorlab's reverse engineering further revealed a multi-stage loader chain: Stage 1 (LumoLight trojanized flashlight app), Stage 2 (Firebase-driven orchestrator with FCM C2), Stage 3 (helper payload/cryptominer), and Stage 4 (full operator RAT). The loader deploys native-code bootstrap libraries that decrypt and load DEX payloads entirely in memory, never writing them to disk, evading static analysis.

BTMOB's evolution from a single-operator centralized service to a fragmented ecosystem involving resellers, impersonators, and independent server operators illustrates how MaaS operations splinter when source code is sold and operator disputes arise, creating a persistent and expanding threat to Android users worldwide.

MITRE ATT&CK techniques used in TL-2026-1841

Execution

T1204 User Execution

defense-evasion

T1406 Obfuscated Files or Information; T1516 Input Injection; T1628 Hide Artifacts; T1630 Indicator Removal on Host; T1655 Masquerading

collection

T1414 Clipboard Data; T1417 Input Capture

discovery

T1418 Software Discovery

Discovery

T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1424 Process Discovery; T1426 System Information Discovery

Collection

T1429 Audio Capture; T1513 Screen Capture; T1533 Data from Local System; T1636 Protected User Data

command-and-control

T1437 Application Layer Protocol

Persistence

T1543 Create or Modify System Process; T1546 Event Triggered Execution; T1624 Event Triggered Execution

Credential Access

T1552 Unsecured Credentials

Defense Evasion

T1574 Hijack Execution Flow; T1622 Debugger Evasion

initial-access

T1660 Phishing

Affected products and versions in Inside the Underground Business of the BTMOB Android RAT

  • Google — Android
    Vulnerable versions: Android 9 through 14

Remediation for Inside the Underground Business of the BTMOB Android RAT

Immediate actions

  • Block known C2 IP addresses (78.135.93.123, 195.160.221.203, and 20+ others) and domains (server.yaarsa.com, btmobrat.net, thebtmob.com) at network perimeter
  • Deploy detection rules for WebSocket connections to known C2 infrastructure on port 8080
  • Scan enterprise-managed Android devices for known malicious package names (com.bitmavrick.lumolight, com.yqzg.parrnell, com.sywo.chelingas, connector.predictor.messenger)
  • Scan for IOCs including 59+ SHA256 hashes published by Unit42
  • Enable Google Play Protect on all Android devices

Workarounds

  • Disable sideloading of apps from outside official app stores on enterprise devices
  • Educate users to never grant Accessibility Service permissions to untrusted apps
  • Instruct users to verify app authenticity before installation, particularly for branded apps from unofficial sources

Longer-term hardening

  • Deploy mobile threat defense (MTD) solution with behavioral detection for Accessibility Service abuse
  • Implement device-integrity attestation for enterprise app access
  • Monitor for unexpected FCM registration by hidden or decoy packages
  • Establish baseline monitoring for foreground-service notifications from unknown packages
  • Deploy network-level detection of cryptomining pool connections (pool.fud2026.com)

Weaknesses (CWE) in Inside the Underground Business of the BTMOB Android RAT

CWE-269, CWE-494, CWE-522, CWE-287, CWE-200

Timeline of Inside the Underground Business of the BTMOB Android RAT

  • SpySolr malware precursor family active; earliest BTMOB variants in development
  • BTMOB v2.5 emerges with approximately 15 samples spotted within two weeks; operator claims 4,000+ mobile devices connected to shared C2 infrastructure
  • Cyble publishes first public technical analysis of BTMOB v2.5, documenting C2 infrastructure (server.yaarsa.com, 78.135.93.123), 16 command capabilities, and WebSocket protocol
  • Palo Alto Networks Unit 42 publishes 59 APK SHA256 hashes and 12 C2 IP addresses from campaigns impersonating Starlink, Chrome, Avast, Roku, and Amazon targeting Latin American users
  • BTMOB original operator offers full source code (PHP/Node.js server, VB.NET control panel, Java Android payload) at $20,000; source includes setup tutorials
  • Dispute between BTMOB administrators escalates; Spanish/Portuguese support channel suspends sales; temporary server outages reported; source code price drops to $10,000
  • Official channel announces administrators will begin operating independently; Brazilian administrator purchases source code and maintains separate version; market fragmentation begins
  • BTMOB V4 released emphasizing lifetime access and private server options; ecosystem continues fragmenting with multiple reseller offers
  • Dark web forum offers BTMOB source code and builder files for free download; ESET publishes detection signatures including Android/Spy.Agent.EIJ and Android/TrojanDropper.Agent.NES
  • BTMOB V4.1 officially released; pricing drops to $1,200 lifetime license; resellers offer V4.1.2 and V4.2 at $500 lifetime
  • BeatBanker variant discovered posing as Starlink app in Brazil; Kaspersky reports hybrid banking trojan + cryptominer (modified XMRig v6.17.0 ARM) with BTMOB RAT payload deployment
  • Zimperium publishes analysis of BTMOB v2.6-v3.2 targeting Alipay PINs via transparent overlay injection; 32 droppers and 44 payloads documented
  • BTMOB V4.5 introduces multiple server locations and central multi-server management page; server source code only offered at $7,000
  • Ostorlab publishes reverse engineering of 4-stage loader chain (LumoLight trojanized flashlight app, Firebase orchestrator, cryptominer, RAT); D3Lab releases leaked C2 source code analysis
  • ESET publishes comprehensive deep-dive analysis of BTMOB v4.6 capabilities, stealth mechanisms, and detection challenges on WeLiveSecurity
  • Flare publishes underground market analysis documenting entire BTMOB ecosystem; BleepingComputer reports detailed pricing, version history, Telegram channels, and ecosystem fragmentation

Sources cited for Inside the Underground Business of the BTMOB Android RAT

Detection coverage for TL-2026-1841

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1841 across Splunk SPL, Microsoft KQL and Sigma, covering 48 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
48 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1841

8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats