Threat reportMalwareTL-2026-1841
Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
Inside the Underground Business of the BTMOB Android RAT (TL-2026-1841), also tracked as BeatBanker, is a high-severity malware campaign, first published 2026-08-03. It is attributed to EVLF with medium confidence, affects Google Android, maps to 25 MITRE ATT&CK techniques (T1204, T1406, T1414), and is covered by 9 detection rules and 48 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1EVLF
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 48Indicators of compromise
Key facts for TL-2026-1841
- Threat ID
- TL-2026-1841
- Also known as
- BeatBanker, SpySolr
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- EVLF
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency, telecoms
- Target regions
- brazil, Latin America, argentina, turkey
- Detection rules
- 9
- Indicators of compromise
- 48
Malware and tooling in Inside the Underground Business of the BTMOB Android RAT
Malware and tooling: BTMOB, xmrig, BTMob.exe
How Inside the Underground Business of the BTMOB Android RAT works
BTMOB is a sophisticated Android remote access trojan sold as a malware-as-a-service (MaaS) package enabling full device takeover, credential theft via dynamic HTML injection overlays, live screen streaming, keylogging, SMS/2FA interception, and cryptomining. Originally operated as a centralized service from at least January 2025 (v2.5), the ecosystem fragmented through 2025-2026 into independently managed versions, cheaper reseller copies, and competing sales channels following source code sales (originally $20,000) and operator disputes in mid-2025. Multiple security vendors — Cyble, Palo Alto Networks Unit 42, ESET, Zimperium, Flare, D3Lab, Ostorlab — have published detailed technical analyses documenting its evolution through at least v4.6, with source code and cracked copies circulating in the secondary market, lowering the barrier for threat actors globally.
BTMOB (evolved from the SpySolr malware family) is an Android Remote Access Trojan (RAT) sold as a commercial Malware-as-a-Service platform. The malware is distributed through phishing websites impersonating legitimate services — including SpaceX Starlink, Google Chrome, Avast Antivirus, Roku, Amazon, GB WhatsApp, and Bradesco — with region-tailored lures targeting primarily Latin American users, particularly Brazil.
Upon installation, BTMOB requests Android Accessibility Service permissions (BIND_ACCESSIBILITY_SERVICE) under the guise of device optimization or protection. Once granted, it auto-grants all other permissions, disables Google Play Protect, hides its icon from the launcher, and acquires a WakeLock to prevent device sleep. The malware maintains persistence through BOOT_COMPLETED broadcast receivers and a foreground service with a fake "Update Now" system notification.
The RAT communicates with its C2 infrastructure via persistent WebSocket connections (supplemented by HTTP fallback and Firebase Cloud Messaging) and supports 16+ remote commands: screen streaming and capture via the MediaProjection API (VNC-like live control with sub-actions for screen block, paste, navigation, gesture injection), WebView-based phishing overlay injection targeting banking and cryptocurrency applications, keylogging and clipboard monitoring, SMS/contact/location harvesting, microphone recording, file management (including AES encryption), fake chat window display, device lock/unlock via pattern/PIN/password replay (using dispatchGesture API and Accessibility Service), and an on-device cryptominer (modified XMRig v6.17.0 ARM) for passive revenue generation.
The C2 backend (recovered by D3Lab analysis of leaked source code) is a centralized SaaS platform built on Apache 2.4.52 with PHP 8.1.2, Node.js Express on port 3000, MariaDB, WebSocket services on port 8080, and RDP on port 3389. The codebase is organized under a directory named "yaarsa" with user/ and private/ paths containing dozens of PHP command handlers. Critically, the operator authentication flows through the developer's backend: customers obtain session tokens (with 2FA) and the actual APK compilation occurs remotely on the threat actor's server, meaning the developer retains unrestricted access to every victim managed by every paying customer.
A particularly sophisticated capability documented by Zimperium targets Alipay PINs via transparent overlay injection — the malware monitors the UI for Alipay's PIN pad, overlays transparent views over each numeric button, captures taps via gesture injection, and exfiltrates digits in real-time with context label "Alipay|PIN|<digit>". Ostorlab's reverse engineering further revealed a multi-stage loader chain: Stage 1 (LumoLight trojanized flashlight app), Stage 2 (Firebase-driven orchestrator with FCM C2), Stage 3 (helper payload/cryptominer), and Stage 4 (full operator RAT). The loader deploys native-code bootstrap libraries that decrypt and load DEX payloads entirely in memory, never writing them to disk, evading static analysis.
BTMOB's evolution from a single-operator centralized service to a fragmented ecosystem involving resellers, impersonators, and independent server operators illustrates how MaaS operations splinter when source code is sold and operator disputes arise, creating a persistent and expanding threat to Android users worldwide.
MITRE ATT&CK techniques used in TL-2026-1841
Execution
defense-evasion
T1406 Obfuscated Files or Information; T1516 Input Injection; T1628 Hide Artifacts; T1630 Indicator Removal on Host; T1655 Masquerading
collection
T1414 Clipboard Data; T1417 Input Capture
discovery
Discovery
T1420 File and Directory Discovery; T1422 System Network Configuration Discovery; T1424 Process Discovery; T1426 System Information Discovery
Collection
T1429 Audio Capture; T1513 Screen Capture; T1533 Data from Local System; T1636 Protected User Data
command-and-control
T1437 Application Layer Protocol
Persistence
T1543 Create or Modify System Process; T1546 Event Triggered Execution; T1624 Event Triggered Execution
Credential Access
Defense Evasion
T1574 Hijack Execution Flow; T1622 Debugger Evasion
initial-access
Affected products and versions in Inside the Underground Business of the BTMOB Android RAT
- Google — Android
Vulnerable versions: Android 9 through 14
Remediation for Inside the Underground Business of the BTMOB Android RAT
Immediate actions
- Block known C2 IP addresses (78.135.93.123, 195.160.221.203, and 20+ others) and domains (server.yaarsa.com, btmobrat.net, thebtmob.com) at network perimeter
- Deploy detection rules for WebSocket connections to known C2 infrastructure on port 8080
- Scan enterprise-managed Android devices for known malicious package names (com.bitmavrick.lumolight, com.yqzg.parrnell, com.sywo.chelingas, connector.predictor.messenger)
- Scan for IOCs including 59+ SHA256 hashes published by Unit42
- Enable Google Play Protect on all Android devices
Workarounds
- Disable sideloading of apps from outside official app stores on enterprise devices
- Educate users to never grant Accessibility Service permissions to untrusted apps
- Instruct users to verify app authenticity before installation, particularly for branded apps from unofficial sources
Longer-term hardening
- Deploy mobile threat defense (MTD) solution with behavioral detection for Accessibility Service abuse
- Implement device-integrity attestation for enterprise app access
- Monitor for unexpected FCM registration by hidden or decoy packages
- Establish baseline monitoring for foreground-service notifications from unknown packages
- Deploy network-level detection of cryptomining pool connections (pool.fud2026.com)
Weaknesses (CWE) in Inside the Underground Business of the BTMOB Android RAT
Timeline of Inside the Underground Business of the BTMOB Android RAT
- SpySolr malware precursor family active; earliest BTMOB variants in development
- BTMOB v2.5 emerges with approximately 15 samples spotted within two weeks; operator claims 4,000+ mobile devices connected to shared C2 infrastructure
- Cyble publishes first public technical analysis of BTMOB v2.5, documenting C2 infrastructure (server.yaarsa.com, 78.135.93.123), 16 command capabilities, and WebSocket protocol
- Palo Alto Networks Unit 42 publishes 59 APK SHA256 hashes and 12 C2 IP addresses from campaigns impersonating Starlink, Chrome, Avast, Roku, and Amazon targeting Latin American users
- BTMOB original operator offers full source code (PHP/Node.js server, VB.NET control panel, Java Android payload) at $20,000; source includes setup tutorials
- Dispute between BTMOB administrators escalates; Spanish/Portuguese support channel suspends sales; temporary server outages reported; source code price drops to $10,000
- Official channel announces administrators will begin operating independently; Brazilian administrator purchases source code and maintains separate version; market fragmentation begins
- BTMOB V4 released emphasizing lifetime access and private server options; ecosystem continues fragmenting with multiple reseller offers
- Dark web forum offers BTMOB source code and builder files for free download; ESET publishes detection signatures including Android/Spy.Agent.EIJ and Android/TrojanDropper.Agent.NES
- BTMOB V4.1 officially released; pricing drops to $1,200 lifetime license; resellers offer V4.1.2 and V4.2 at $500 lifetime
- BeatBanker variant discovered posing as Starlink app in Brazil; Kaspersky reports hybrid banking trojan + cryptominer (modified XMRig v6.17.0 ARM) with BTMOB RAT payload deployment
- Zimperium publishes analysis of BTMOB v2.6-v3.2 targeting Alipay PINs via transparent overlay injection; 32 droppers and 44 payloads documented
- BTMOB V4.5 introduces multiple server locations and central multi-server management page; server source code only offered at $7,000
- Ostorlab publishes reverse engineering of 4-stage loader chain (LumoLight trojanized flashlight app, Firebase orchestrator, cryptominer, RAT); D3Lab releases leaked C2 source code analysis
- ESET publishes comprehensive deep-dive analysis of BTMOB v4.6 capabilities, stealth mechanisms, and detection challenges on WeLiveSecurity
- Flare publishes underground market analysis documenting entire BTMOB ecosystem; BleepingComputer reports detailed pricing, version history, Telegram channels, and ecosystem fragmentation
Sources cited for Inside the Underground Business of the BTMOB Android RAT
- Inside the Underground Business of the Android BTMOB RAT Malware
- BTMOB RAT: Newly Discovered Android Malware
- Unit 42 IOCs for BTMOB RAT Activity
- BTMOB: A Stealthy RAT Burrowing Deep into Android Devices
- From Lock Screen to Wallets: BTMOB RAT Now Targets Alipay PINs
- Inside BTMOB: An Analytical Breakdown of a Leaked Android RAT Ecosystem
- Inside BeatBanker/BTMOB: Reverse Engineering a Multi-Stage Android Banking Malware
- New BeatBanker Android Malware Poses as Starlink App
- Flare: BTMOB RAT Underground Market Analysis
- Campaign Targeting Latin American Users Distributing BTMOB RAT
- BTMOB RAT: Full Device Takeover MaaS
- BTMOB RAT Easy-to-Use Builder
Detection coverage for TL-2026-1841
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1841 across Splunk SPL, Microsoft KQL and Sigma, covering 48 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1841
8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.