# Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service

> BTMOB is a sophisticated Android remote access trojan sold as a malware-as-a-service (MaaS) package enabling full device takeover, credential theft via dynamic HTML injection overlays, live screen streaming, keylogging, SMS/2FA interception, and cryptomining. Originally operated as a centralized service from at least January 2025 (v2.5), the ecosystem fragmented through 2025-2026 into independently managed versions, cheaper reseller copies, and competing sales channels following source code sales (originally $20,000) and operator disputes in mid-2025. Multiple security vendors — Cyble, Palo Alto Networks Unit 42, ESET, Zimperium, Flare, D3Lab, Ostorlab — have published detailed technical analyses documenting its evolution through at least v4.6, with source code and cracked copies circulating in the secondary market, lowering the barrier for threat actors globally.

- **Published:** 2026-08-03T00:00:00Z
- **Last reviewed:** 2026-08-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1841
- **ID:** TL-2026-1841
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** EVLF
- **Detections:** 9 · **IOCs:** 48 (full data via the Threadlinqs MCP server — Purple tier)

## Description

BTMOB (evolved from the SpySolr malware family) is an Android Remote Access Trojan (RAT) sold as a commercial Malware-as-a-Service platform. The malware is distributed through phishing websites impersonating legitimate services — including SpaceX Starlink, Google Chrome, Avast Antivirus, Roku, Amazon, GB WhatsApp, and Bradesco — with region-tailored lures targeting primarily Latin American users, particularly Brazil.

Upon installation, BTMOB requests Android Accessibility Service permissions (BIND_ACCESSIBILITY_SERVICE) under the guise of device optimization or protection. Once granted, it auto-grants all other permissions, disables Google Play Protect, hides its icon from the launcher, and acquires a WakeLock to prevent device sleep. The malware maintains persistence through BOOT_COMPLETED broadcast receivers and a foreground service with a fake "Update Now" system notification.

The RAT communicates with its C2 infrastructure via persistent WebSocket connections (supplemented by HTTP fallback and Firebase Cloud Messaging) and supports 16+ remote commands: screen streaming and capture via the MediaProjection API (VNC-like live control with sub-actions for screen block, paste, navigation, gesture injection), WebView-based phishing overlay injection targeting banking and cryptocurrency applications, keylogging and clipboard monitoring, SMS/contact/location harvesting, microphone recording, file management (including AES encryption), fake chat window display, device lock/unlock via pattern/PIN/password replay (using dispatchGesture API and Accessibility Service), and an on-device cryptominer (modified XMRig v6.17.0 ARM) for passive revenue generation.

The C2 backend (recovered by D3Lab analysis of leaked source code) is a centralized SaaS platform built on Apache 2.4.52 with PHP 8.1.2, Node.js Express on port 3000, MariaDB, WebSocket services on port 8080, and RDP on port 3389. The codebase is organized under a directory named "yaarsa" with user/ and private/ paths containing dozens of PHP command handlers. Critically, the operator authentication flows through the developer's backend: customers obtain session tokens (with 2FA) and the actual APK compilation occurs remotely on the threat actor's server, meaning the developer retains unrestricted access to every victim managed by every paying customer.

A particularly sophisticated capability documented by Zimperium targets Alipay PINs via transparent overlay injection — the malware monitors the UI for Alipay's PIN pad, overlays transparent views over each numeric button, captures taps via gesture injection, and exfiltrates digits in real-time with context label "Alipay|PIN|<digit>". Ostorlab's reverse engineering further revealed a multi-stage loader chain: Stage 1 (LumoLight trojanized flashlight app), Stage 2 (Firebase-driven orchestrator with FCM C2), Stage 3 (helper payload/cryptominer), and Stage 4 (full operator RAT). The loader deploys native-code bootstrap libraries that decrypt and load DEX payloads entirely in memory, never writing them to disk, evading static analysis.

BTMOB's evolution from a single-operator centralized service to a fragmented ecosystem involving resellers, impersonators, and independent server operators illustrates how MaaS operations splinter when source code is sold and operator disputes arise, creating a persistent and expanding threat to Android users worldwide.

## MITRE ATT&CK

- T1660 Phishing
- T1204 User Execution
- T1624 Event Triggered Execution
- T1546 Event Triggered Execution
- T1543 Create or Modify System Process
- T1655 Masquerading
- T1628 Hide Artifacts
- T1406 Obfuscated Files or Information
- T1630 Indicator Removal on Host
- T1574 Hijack Execution Flow
- T1418 Software Discovery
- T1622 Debugger Evasion
- T1516 Input Injection
- T1417 Input Capture
- T1414 Clipboard Data
- T1552 Unsecured Credentials
- T1420 File and Directory Discovery
- T1424 Process Discovery
- T1426 System Information Discovery
- T1422 System Network Configuration Discovery
- T1429 Audio Capture
- T1513 Screen Capture
- T1533 Data from Local System
- T1636 Protected User Data
- T1437 Application Layer Protocol

## Sources

- [Inside the Underground Business of the Android BTMOB RAT Malware](https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/)
- [BTMOB RAT: Newly Discovered Android Malware](https://cyble.com/blog/btmob-rat-newly-discovered-android-malware/)
- [Unit 42 IOCs for BTMOB RAT Activity](https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-05-21-IOCs-for-BTMOB-RAT-activity.txt)
- [BTMOB: A Stealthy RAT Burrowing Deep into Android Devices](https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/)
- [From Lock Screen to Wallets: BTMOB RAT Now Targets Alipay PINs](https://zimperium.com/blog/from-lock-screen-to-wallets-btmob-rat-now-targets-alipay-pins)
- [Inside BTMOB: An Analytical Breakdown of a Leaked Android RAT Ecosystem](https://www.d3lab.net/inside-btmob-an-analytical-breakdown-of-a-leaked-android-rat-ecosystem/)
- [Inside BeatBanker/BTMOB: Reverse Engineering a Multi-Stage Android Banking Malware](https://medium.com/@ostorlab/inside-beatbanker-btmob-reverse-engineering-a-multi-stage-android-banking-malware-remote-access-bf01aee85cfe)
- [New BeatBanker Android Malware Poses as Starlink App](https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/)
- [Flare: BTMOB RAT Underground Market Analysis](https://flare.io/blog/)
- [Campaign Targeting Latin American Users Distributing BTMOB RAT](https://gurucul.com/latest-threats/campaign-targeting-latin-american-users-distributing-btmob-rat-android-malware/)
- [BTMOB RAT: Full Device Takeover MaaS](https://cipherssecurity.com/btmob-android-rat-full-device-takeover-maas/)
- [BTMOB RAT Easy-to-Use Builder](https://threataft.com/articles/btmob-android-rat-easy-to-use-builder)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1841
