Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service — Threadlinqs Intelligence
As of 2026-08-03, Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service is a high-severity malware threat attributed to EVLF, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 48 indicators of compromise.
Threat ID: TL-2026-1841 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: EVLF · FINANCIAL
BTMOB is a sophisticated Android remote access trojan sold as a malware-as-a-service (MaaS) package enabling full device takeover, credential theft via dynamic HTML injection overlays, live screen
BTMOB (evolved from the SpySolr malware family) is an Android Remote Access Trojan (RAT) sold as a commercial Malware-as-a-Service platform. The malware is distributed through phishing websites impersonating legitimate services — including SpaceX Starlink, Google Chrome, Avast Antivirus, Roku, Amazon, GB WhatsApp, and Bradesco — with region-tailored lures targeting primarily Latin American users, particularly Brazil.
Upon installation, BTMOB requests Android Accessibility Service permissions (BIND_ACCESSIBILITY_SERVICE) under the guise of device optimization or protection. Once granted, it auto-grants all other permissions, disables Google Play Protect, hides its icon from the launcher, and acquires a WakeLock to prevent device sleep. The malware maintains persistence through BOOT_COMPLETED broadcast receivers and a foreground service with a fake "Update Now" system notification.
The RAT communicates with its C2 infrastructure via persistent WebSocket connections (supplemented by HTTP fallback and Firebase Cloud Messaging) and supports 16+ remote commands: screen streaming and capture via the MediaProjection API (VNC-like live control with sub-actions for screen block, paste, navigation, gesture injection), WebView-based phishing overlay injection targeting banking and cryptocurrency applications, keylogging and clipboard monitoring, SMS/contact/location harvesting, microphone recording, file management (including AES encryption), fake chat window display, device lock/unlock via pattern/PIN/password replay (using dispatchGesture API and Accessibility Service), and an on-device cryptominer (modified XMRig v6.17.0 ARM) for passive revenue generation.
The C2 backend (recovered by D3Lab analysis of leaked source code) is a centralized SaaS platform built on Apache 2.4.52 with PHP 8.1.2, Node.js Express on port 3000, MariaDB, WebSocket services on port 8080, and RDP on port 3389. The codebase is organized under a directory named "yaarsa" with user/ and private/ paths containing dozens of PHP command handlers. Critically, the operator authentication flows through the developer's backend: customers obtain session tokens (with 2FA) and the actual APK compilation occurs remotely on the threat actor's server, meaning the developer retains unrestricted access to every victim managed by every paying customer.
A particularly sophisticated capability documented by Zimperium targets Alipay PINs via transparent overlay injection — the malware monitors the UI for Alipay's PIN pad, overlays transparent views over each numeric button, captures taps via gesture injection, and exfiltrates digits in real-time with context label "Alipay|PIN|<digit>". Ostorlab's reverse engineering further revealed a multi-stage loader chain: Stage 1 (LumoLight trojanized flashlight app), Stage 2 (Firebase-driven orchestrator with FCM C2), Stage 3 (helper payload/cryptominer), and Stage 4 (full operator RAT). The loader deploys native-code bootstrap libraries that decrypt and load DEX payloads entirely in memory, never writing them to disk, evading static analysis.
BTMOB's evolution from a single-operator centralized service to a fragmented ecosystem involving resellers, impersonators, and independent server operators illustrates how MaaS operations splinter when source code is sold and operator disputes arise, creating a persistent and expanding threat to Android users worldwide.
Weaknesses (CWE)
CWE-269, CWE-494, CWE-522, CWE-287, CWE-200
Target sectors: finance, cryptocurrency, telecoms
Target regions: brazil, Latin America, argentina, turkey
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 48 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1204, T1624, T1546, T1543, T1655, T1628, T1406, T1630, T1574