BTMOB started as a centrally run Android RAT malware-as-a-service operation, but it has since splintered into a fragmented underground market of resellers, source-code vendors, independent server operators, and impersonators. Flare researchers found that the official channel kept releasing new versions and infrastructure offers while cheaper and sometimes unverified BTMOB listings spread across Telegram and other platforms. #BTMOB #Flare #Telegram
Keypoints
- BTMOB evolved from a single MaaS operation into a wider ecosystem of sellers and operators.
- The official channel repeatedly lowered prices and offered access, private servers, and source code.
- Third parties advertised cheaper BTMOB subscriptions, panels, and alleged source files.
- Telegram campaigns spread BTMOB offers using similar wording, pricing, and contact handles.
- The BTMOB name now covers multiple versions and sellers with uncertain legitimacy.
Read More: https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/