From Lock Screen to Wallets: BTMOB RAT Now Targets Alipay PINs

On February 12, researchers at Cyble announced a new variant of BTMOB spyware, identified as BTMOB RAT v2.5, which spreads through phishing sites posing as popular streaming services and cryptocurrency platforms. Subsequent investigations revealed additional variants, with new delivery methods involving deceptive updates. The spyware is capable of stealing lock screen credentials and interacting with the Alipay application through overlay attacks. This threat poses significant risks to mobile users through various distribution methods that mimic legitimate applications. Affected: mobile devices, online streaming services, cryptocurrency platforms, and financial applications.

Keypoints :

  • Discovery of BTMOB RAT v2.5 and its subsequent versions (v2.6 to v3.2).
  • Distribution through phishing sites impersonating streaming services and cryptocurrency mining platforms.
  • Utilization of 32 droppers and 44 payloads mimicking legitimate applications.
  • Delivery via fake websites designed to trick users.
  • Involvement of open directories for malware distribution.
  • Ability to steal lock screen credentials using overlay attacks.
  • New feature capturing Alipay PINs by exploiting Accessibility Service.

MITRE Techniques :

  • Initial Access (T1660) – Phishing: Sending malicious content to gain device access.
  • Persistence (T1624.001) – Event Triggered Execution: Broadcast Receivers: Launches automatically on device reboot.
  • Defense Evasion (T1655.001) – Masquerading: Match Legitimate Name or Location: Pretends to be a genuine app.
  • Defense Evasion (T1516) – Input Injection: Mimics user interaction and performs input actions.
  • Defense Evasion (T1406.002) – Obfuscated Files or Information: Software Packing: Uses string obfuscation.
  • Credential Access (T1414) – Clipboard Data: Extracts clipboard data.
  • Credential Access (T1417.001) – Input Capture: Keylogging: Has a keylogging feature.
  • Exfiltration (T1646) – Exfiltration Over C2 Channel: Sends exfiltrated data to C&C server.

Indicator of Compromise :

  • No explicit IOCs were provided in the text. Please refer to the linked repository for potential IOCs.

Full Story: https://zimperium.com/blog/from-lock-screen-to-wallets-btmob-rat-now-targets-alipay-pins