BTMOB RAT

Malware type
rat, credential-stealer, keylogger, screen-capture
Family
Malware family
Last IoC activity
2026-07-17 21:27:18
Profile updated
2026-07-07 14:04:48

Targeted industries: media-and-entertainment financial-services

Context

According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration. It spreads via phishing sites impersonating streaming services like iNat TV and fake mining platforms. The malware abuses Android’s Accessibility Service to unlock devices, log keystrokes, and automate credential theft through injections. It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Btmob (report)
  • any.run — Btmob (report)
  • cyble.com — Btmob Rat Newly Discovered Android Malware (report)

External references