Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BTMOB RAT

66
Global rank
43 infographic chevron month
Month rank
48 infographic chevron week
Week rank
0
IOCs

BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

RAT
Type
Unknown
Origin
1 February, 2025
First seen
29 August, 2026
Last seen

How to analyze BTMOB RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2025
First seen
29 August, 2026
Last seen

IOCs

IP addresses
185.100.157.103
54.77.237.253
188.114.96.3
142.251.127.81
192.178.183.100
142.251.157.119
188.114.97.3
192.178.183.113
216.239.35.12
142.251.13.94
52.215.48.123
142.251.154.119
142.251.152.119
216.239.35.8
142.251.156.119
142.251.153.119
80.91.86.128
142.251.151.119
34.104.35.123
142.250.154.138
Hashes
1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
d97351f73a01b039488790a20c550a0985fed6ce6af25fbd14553b6d7788c6e0
9b0ac791a3fa953e28b526e020fd2e629b40812ee1bc4693ff5fdfef15044202
378694706fb7256dd2248e2af854efd71ec7e8885f61da2e16a2bd32fcf3d0a9
5a6ca1d0d2fea53813da5b3c9037408087f9f753f58dd2e128a4a48f7689769f
25f25112cc46b285767de7b5b058cfc0a9efd5f21cfe724af031505d66a9eceb
932b2f1a5d1f714742551df4e25b78af1d68d8c3972a3d97ad8d2c24dc13777b
4bc8f4d13d2acccc1338f73ff90cd97695d9210e04de5da924215243c8950bf3
9fd37c82f87df00464554344ddddea55e480d09c33b505ac13252036d4d6276e
4a5c839ab0ce8c0b23a47091bf6a69392c6e11e7e02f31e0889f12c0b1a27cca
296d14b94eb56e0e458aef7bb1e3e14bcd2a3ead9003caf905bf7169ff441027
4ce49f0551a23930593efd94310ce157d187a18e017849922c4a666a8ee4186d
7692b3890873f747082a599d0074601514b73b2861908a9b8fa47d6f99ee1228
d25d077d3cfa78fa3548c8d07f18b1c7fb7c8850bf6056ca2a8b954e9b2b11c6
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
98ab3a3c18fcb237528dd63fa489815c583e1d6c13debd2a27ac6d74ccf8717b
3b9d18d5cc3af6c0cb3e903327ae3da35634c7c3a0b11413b9a3b1c10c640d5e
df15aa3ca5a62636a0c906b1e766c7d3dd8b7acb13f52720ef4f466ba8f54706
67d0c25c964c23d04f41eee06ec9aa9cc7946e24e73a8d8d920b1c1f359b235e
Domains
google.com
clientservices.googleapis.com
www.google.com
checkip.amazonaws.com
connectivitycheck.gstatic.com
dhdjhebw.icu
staging-remoteprovisioning.sandbox.googleapis.com
update.googleapis.com
edgedl.me.gvt1.com
up.mylighting04.ink
clubvip.store
fonts.googleapis.com
www.gstatic.com
dl.google.com
time.android.com
cdnjs.cloudflare.com
content-autofill.googleapis.com
fonts.gstatic.com
www.recaptcha.net
play.googleapis.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://update.googleapis.com/service/update2/json?cup2key=15:utxc8mqxt-cx-odj7dzvlxpv5_vzrb7mk3uoodhjtk4&cup2hreq=dc5180313986e648af77bb95991c0f2d688559eb3c43306ae78c92348bd93af6
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboe6q6aobilstywnqamw9ses57wrumsffj2y=&request_id=7f109280-6f24-4e48-8076-107657d7f0e5
http://185.100.157.103/s/private/yarsap_80541.php
https://dhdjhebw.icu/yaarsa/con
http://checkip.amazonaws.com/
http://185.100.157.103:47483/data?sessionid=b55ef2e4-92a1-4f1f-b6f2-fbff9e39d297
http://185.100.157.103:51589/control?sessionid=b55ef2e4-92a1-4f1f-b6f2-fbff9e39d297
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboeznzwwbilstywr72ppwmtsuldcsdlqrfpe=&request_id=8ef30308-2be3-4fbb-a018-d09ecc7db4fc
http://185.100.157.103:47483/data?sessionid=3146b7f2-17a1-435b-84a1-b01c321ae49c
http://185.100.157.103:51589/control?sessionid=3146b7f2-17a1-435b-84a1-b01c321ae49c
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboewyn7abilsty-xrmgaqgrqahn1maofm6xs=&request_id=a52cefcb-4ef5-4091-a8c5-886fda2f2a05
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://update.googleapis.com/service/update2/json?cup2key=15:rihwts_1awc-asfbbxjts0ekhnnuxkrj2pgru6em_w0&cup2hreq=984e565b7ea5d911a0dc3e909505e6fbb65471105a951a96d1051366ed6d6352
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
http://80.91.86.128/panel/private/connect.php
https://up.mylighting04.ink/api/shell-event?track_id=1786987638825-x4vce&event=shell_first_open&inner_pkg=adwce.rb5u.dx8gs.f1l&k=sk8mn2pq9xr4vl7wt5yh3jf6ab1cd0e&t=1787895846988
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4136
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10033
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 12522
comments 0

BTMOB RAT: The Android Phantom Hijacking Your Wallet

Key Takeaways

  1. Commercial-Grade Mobile Malware: BTMOB RAT operates as Malware-as-a-Service with lifetime licenses selling for $5,000, representing a dangerous shift toward professionalized mobile threats with rapid development cycles.
  2. Beyond Traditional Mobile Malware: This isn't just another Android trojan: it combines live screen control, banking overlay attacks, cryptocurrency theft, and comprehensive surveillance capabilities that rival desktop RATs.
  3. Accessibility Service Weaponization: The malware exploits Android's accessibility features designed for disabled users, turning assistive technology into a powerful attack vector that bypasses most traditional mobile security measures.
  4. Financial Services in the Crosshairs: With specialized capabilities targeting Alipay and banking apps through real-time overlay attacks, BTMOB RAT represents a new era of mobile financial fraud that threatens both personal and corporate banking security.
  5. Defense Strategies: Detect via IOCs like specific domains and behavioral anomalies; prevent with app vetting, updates, and MTD tools; leverage threat intelligence for proactive blocking and variant tracking.

BTMOB RAT IOCs in Interactive Sandbox Gather BTMOB RAT IOCs in ANY.RUN's Interactive Sandbox

What is BTMOB RAT Malware?

BTMOB RAT represents a significant evolution in Android malware, emerging as one of the most sophisticated Remote Access Trojans targeting mobile devices in 2025. This advanced malware evolved from the SpySolr family and has rapidly gained notoriety for its comprehensive data theft capabilities, remote control features, and ability to bypass modern Android security measures. With over 15 variants identified since December 2024, BTMOB RAT poses a serious threat to both individual users and organizations worldwide. The malware operates as a comprehensive Remote Access Trojan specifically designed for Android platforms, leveraging the operating system's Accessibility Service to gain extensive control over infected devices. Unlike traditional mobile malware that focuses on single attack vectors, BTMOB RAT combines multiple techniques including credential theft, remote device control, banking fraud, and data exfiltration capabilities.

What sets BTMOB RAT apart from other mobile threats is its sophisticated use of overlay attacks, particularly targeting financial applications like Alipay. The latest version (v2.5) incorporates advanced obfuscation techniques and can perform real-time screen manipulation.

The malware is distributed through a Malware-as-a-Service (MaaS) model, with cybercriminals advertising lifetime licenses for $5,000 through Telegram channels. This commercial approach has accelerated its adoption among threat actors and contributed to its rapid evolution and widespread distribution.

BTMOB RAT infiltrates via social engineering, primarily phishing sites masquerading as legitimate apps like iNat TV (e.g., tvipguncelpro.com) or fake WhatsApp mods (e.g., WhatsApp GB). Users are tricked into sideloading APKs, which prompt enabling Accessibility Service—framed as necessary for "enhanced features."

Spread occurs through:

  • Phishing Campaigns: URLs distributed on forums, SMS, or search-engine-indexed fake sites (e.g., Argentine tax agency clones).
  • App Stores and Mods: Malicious apps on Google Play or third-party stores.
  • MaaS Distribution: Developers promote via Telegram, enabling affiliates to customize and deploy.

Post-infection, it self-propagates by exfiltrating contacts for SMS phishing or using infected devices to host phishing pages. Geographic targeting, like Morocco's 2025 alerts, shows adaptation to local lures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

BTMOB RAT Malware Victimology

BTMOB RAT predominantly targets Android users in emerging markets with high mobile banking adoption, where digital financial services are rapidly growing but security awareness lags. In Morocco, it has been a focal point of national alerts, affecting smartphone users who enable accessibility features for convenience, leading to widespread banking data theft. Morocco ranks third in Africa for web-based threats, with over 12.6 million attack attempts in 2024, amplifying BTMOB's impact.

Globally, victims include casual users of streaming or mining apps, as well as financial app users in China (e.g., Alipay targets). Recent campaigns have hit Latin America, such as Argentina via fake government sites impersonating tax agencies. Over 500,000 installations of similar accessibility-abusing malware were recorded in 2024, suggesting BTMOB's victim pool could number in the tens of thousands by September 2025. Businesses in retail and finance are indirect victims through employee devices, but primary targets remain individual consumers vulnerable to phishing.

How BTMOB RAT Functions

The trojan operates through several sophisticated mechanisms:

Accessibility Service Abuse:

It exploits Android's Accessibility Service, originally designed to help users with disabilities, to gain broad system permissions and control over user interface elements.

Overlay Attacks:

BTMOB RAT creates transparent or semi-transparent overlays on legitimate applications, particularly banking and payment apps, to capture user credentials and sensitive information without detection.

Remote Administration:

The malware establishes persistent command and control (C&C) communication channels, allowing attackers to remotely execute commands, update malware components, and extract data in real-time.

Dynamic Code Loading:

Advanced variants can download and execute additional malicious modules, expanding their capabilities based on specific attack objectives.

Anti-Detection Techniques:

The malware employs multiple evasion techniques including code obfuscation, runtime application self-protection (RASP), and behavioral analysis evasion to avoid detection by security solutions.

Data Exfiltration:

Stolen information is encrypted and transmitted to attacker-controlled servers through various channels, including HTTPS connections to legitimate-looking domains.

BTMOB RAT Attack Example and Technical Analysis

A dynamic analysis of a BTMOB sample in ANY.RUN’s Interactive Sandbox reveals key operating mechanisms and network activity of the malware.

View analysis

BTMOB RAT analysis in Interactive Sandbox BTMOB RAT sample analysis in the Interactive Sandbox

Network Activity and Encryption

Analysis of network traffic revealed the malware’s attempts to establish a connection with the command and control (C&C) server via hxxx [://] ip/yaarsa/private/yarsap_80541 [.] php. A characteristic sequence of requests is observed: an initial HEAD request, followed by a repeated HEAD after a pause, which is part of the handshake connection establishment mechanism and server availability check.

BTMOB RAT network connection attempts BTMOB RAT sample analysis in the Interactive Sandbox

All commands and data are transmitted through an encrypted channel, which complicates analysis of the payload. To protect its configuration and the collected data, the malware actively uses cryptographic APIs.

BTMOB RAT uses encryption technique Encryption technique used by BTMOB RAT

Configuration File and Management

BTMOB RAT stores its configuration in the system SharedPreferences storage in XML format. The configuration file contains a complex map of boolean values, where each parameter defines the malware's functionality.

BTMOB RAT configuration file in Interactive Sandbox BTMOB RAT configuration file contents visible in Interactive Sandbox

Persistence and Privilege Escalation Mechanisms

Aggressive permission acquisition appears to be the key attack vector. The malware doesn't simply request access but manipulates the interface using Input Injection to automatically press the "Allow" button.

BTMOB RAT uses input injection BTMOB RAT detected to use Input Injection technique

Once access is obtained, it gains control over the device, including implementing the Prevent Application Removal mechanism, intercepting events in Android Settings to block its own uninstallation.

To ensure continuous operation, the malware creates a background service immediately after launch and uses WakeLock, preventing the device from entering sleep mode. Additionally, it checks the lock screen state, which increases its stealth.

Data Collection and Malicious Activity

Before performing its main tasks, the malware conducts comprehensive reconnaissance: collects a list of installed applications, analyzes running processes, and obtains system data. This allows the operator to adapt the attack to the specific device.

Important malicious activity is conducting overlay attacks. The malware overlays phishing windows on legitimate applications, primarily banking and cryptocurrency ones, to steal credentials, PIN codes, and two-factor authentication.

You can view the succession of the above-mentioned processes in ANY.RUN’s Sandbox as a process tree with every behavior’s description.

BTMOB RAT’s malicious processes BTMOB RAT’s malicious processes

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Notable BTMOB RAT Attacks

While specific large-scale BTMOB attacks are still emerging due to its recent discovery, several notable patterns have been identified:

Streaming Service Impersonation Campaigns:

Multiple campaigns have been observed where attackers created sophisticated fake websites mimicking popular streaming platforms, leading to thousands of downloads before detection.

Cryptocurrency Mining Fraud:

Significant campaigns targeting cryptocurrency enthusiasts through fake mining applications have resulted in substantial financial losses and credential theft.

Alipay PIN Theft Operations:

Recent versions specifically targeting Alipay users have demonstrated the malware's evolution toward financial fraud, with overlay attacks successfully capturing payment credentials.

Corporate Device Compromises:

Several incidents have been reported where employee devices were compromised through entertainment-focused phishing, leading to broader organizational security concerns.

These examples demonstrate the malware's versatility and the threat actors' ability to adapt their tactics based on current trends and user interests.

Gathering Threat Intelligence on BTMOB RAT Malware

Threat intelligence plays a crucial role in defending against BTMOB RAT:

  • Proactive Threat Detection: Intelligence feeds provide early warning indicators of new BTMOB RAT campaigns, enabling organizations to implement protective measures before attacks reach their environments.
  • Attribution and Campaign Tracking: Threat intelligence helps identify the tactics, techniques, and procedures (TTPs) used by BTMOB RAT operators, enabling better prediction and prevention of future attacks.
  • Contextual Analysis: Intelligence provides crucial context about BTMOB RAT variants, helping security teams understand the specific threats relevant to their organization and user base.
  • Predictive Security: Advanced threat intelligence can help predict likely evolution paths for BTMOB RAT, enabling proactive security measure implementation.

Start gathering intelligence by searching BTMOB in ANY.RUN’s Threat Intelligence Lookup. View the RAT’s fresh sample analyses to understand TTPs and harvest IOCs:

threatName:"btmob"

BTMOB RAT’s samples found via Threat Intelligence Lookup BTMOB RAT’s samples found via Threat Intelligence Lookup

Threat Intelligence Lookup is available for free: collect indicators, browse sandbox detonations quick and easy.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BTMOB RAT remains a versatile and dangerous remote access Trojan capable of damaging both individuals and enterprises. Its modular architecture, stealthy operations, and adaptability make it a prime tool for cybercriminals and APT actors alike. Proactive defense powered by advanced detection, prevention strategies, and real-time threat intelligence is essential to reduce risks and prevent devastating breaches.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for timely detection and response.

HAVE A LOOK AT

SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More