BTMOB is an Android remote access trojan sold as a malware-as-a-service platform with a builder that lets criminals create customized phishing-based payloads without coding. It targets users mainly in Brazil and Latin America, using fake Google Play pages, Accessibility abuse, and multiple theft and remote-control features. #BTMOB #SpySolr #ESET #ANYRUN #Cyble
Keypoints
- BTMOB is an Android RAT offered as malware-as-a-service.
- Its builder lets criminals customize APK payloads without coding.
- The malware can steal data, intercept transactions, and take screenshots.
- It spreads through phishing sites posing as streaming, mining, and Google Play pages.
- BTMOB is active mainly in Brazil and Latin America, with campaigns using localized lures.