Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BTMOB RAT

70
Global rank
46 infographic chevron month
Month rank
30 infographic chevron week
Week rank
0
IOCs

BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

RAT
Type
Unknown
Origin
1 February, 2025
First seen
17 August, 2026
Last seen

How to analyze BTMOB RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2025
First seen
17 August, 2026
Last seen

IOCs

IP addresses
142.251.153.119
192.178.183.94
142.251.154.119
199.231.213.123
142.251.157.119
142.251.151.119
142.251.14.94
216.239.35.8
142.251.152.119
142.251.150.119
216.239.35.12
104.21.56.86
49.13.77.253
216.239.35.0
166.0.27.225
142.251.156.119
207.180.3.9
34.104.35.123
108.133.195.133
64.233.166.81
Hashes
b44eeda34d7a529c2fe55719eb098fa29707caa91d18de06a7a775d6e6bcf973
49903073ab23abfc11a55e1333eb2905c743e1b382006c27c15434fd76e0207c
682c466d3e4f39e31f114abc1632d85e734557bd39814e3ba7d7c61eae2d069b
f232714ccbecca97adc63b0811d62629057c77dcbd0b062c82e26754cb744831
6151450ece3ab9667213c3987b6d8fffa25baf9ff43d53bcd9c94fd8ea7616d0
fa50162bdb3501c6b50cfa36c14dab9c94e48d57f558607ec9858124d70412f9
a933aaebbeae489dea84e78e7fbc4079fdfda576fbdeb339401fda6cdc03e764
1411ae65d8160573c166d2a572106fd1103c12f242f67feec5feaa550197e5f5
8430ec003e003f3f2ba2f78d48fd150e25407667e530e82e87a7d4841c0fd676
52549a8d0b6c35faf2795efdf6b4c5fe2cb34b7e8b1039cca7aa2769b6cab3d0
5e3f13ee854fa41354ca7378358b99f8e41f3b1c9968c313b630b02de8704e6e
239d602c9c65f156fe024613207955ac8fbdd395ae6ec3efa51be98e3a4473f4
0d773e62c756422313262846c787e58f67e0ee87e45e1ae9942002e816c4cb9e
0caaea0060b3772ba433c0e9e3a5452f26f3421ba5023c855157270bc675b309
23439b8899f4b63d68ae9385eaa49286a4b95b95f79b8b8d37de3b0e4fdbc747
6b2372b414abc1cfcfd71c98f51901a84c46c5b712046aae019b6110de265175
7c8472b72441cc28a1ac53a08b4f0c14f310af338175ba6c46fd6342ac8ce2ff
aa61229cd70239278109c5ebe725e72484d0252efa4902a17192366942749289
5ae9594240ada5e53500e2524215b3e2b3c91e6dd95b05e0acdd27d9d8c57e72
b800fac7d2f0a75b17fad7009707ea49134919e48984e89815a9d24c0fa704d8
Domains
google.com
www.google.com
beeg.com
yaarsa
connectivitycheck.gstatic.com
tj.apktj.xyz
checkip.amazonaws.com
update.googleapis.com
edgedl.me.gvt1.com
staging-remoteprovisioning.sandbox.googleapis.com
clientservices.googleapis.com
play-lh.googleusercontent.com
www.google-analytics.com
ssl.gstatic.com
fonts.gstatic.com
www.gstatic.com
play.google.com
www.googletagmanager.com
time.android.com
play.googleapis.com
URLs
http://connectivitycheck.gstatic.com/generate_204
http://www.google.com/gen_204
https://www.google.com/generate_204
https://tj.apktj.xyz/install_stat.php?app_name=yzgwurgzlfuf&device_id=realme_x2_pro_build%2fup1a.231105.001.dbf7d390_dev_cio9qo&t=1786965150650
https://tj.apktj.xyz/install_stat.php?app_name=yzgwurgzlfuf&action=update&device_id=realme_x2_pro_dev_106082b38f8d906b
http://166.0.27.225/yaarsa/private/yarsap_80541.php
http://yaarsa/private/yarsap_80541.php
https://beeg.com/
https://beeg.com/favicon.ico
https://update.googleapis.com/service/update2/json?cup2key=15:4s0k2a_yvfcufw4xjbdibavj64jrtel5ac244fdhe9g&cup2hreq=96652cb65d68a77efc59c24b9de7e711233c676d64fdde1c976e2dca4fdb9df1
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
http://207.180.3.9/yaarsa/private/yarsap_80541.php
http://checkip.amazonaws.com/
http://207.180.3.9:8080/
http://185.199.196.147/s/private/yarsap_80541.php
https://play.google.com/store/apps/details?id=de.lhenne.fits
http://185.199.196.147:51589/control?sessionid=8d7e2d07-bfc7-4728-9158-c880a304c186
http://185.199.196.147:47483/data?sessionid=8d7e2d07-bfc7-4728-9158-c880a304c186
Last Seen at

Recent blog posts

post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 379
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 11437
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 6548
comments 0

BTMOB RAT: The Android Phantom Hijacking Your Wallet

Key Takeaways

  1. Commercial-Grade Mobile Malware: BTMOB RAT operates as Malware-as-a-Service with lifetime licenses selling for $5,000, representing a dangerous shift toward professionalized mobile threats with rapid development cycles.
  2. Beyond Traditional Mobile Malware: This isn't just another Android trojan: it combines live screen control, banking overlay attacks, cryptocurrency theft, and comprehensive surveillance capabilities that rival desktop RATs.
  3. Accessibility Service Weaponization: The malware exploits Android's accessibility features designed for disabled users, turning assistive technology into a powerful attack vector that bypasses most traditional mobile security measures.
  4. Financial Services in the Crosshairs: With specialized capabilities targeting Alipay and banking apps through real-time overlay attacks, BTMOB RAT represents a new era of mobile financial fraud that threatens both personal and corporate banking security.
  5. Defense Strategies: Detect via IOCs like specific domains and behavioral anomalies; prevent with app vetting, updates, and MTD tools; leverage threat intelligence for proactive blocking and variant tracking.

BTMOB RAT IOCs in Interactive Sandbox Gather BTMOB RAT IOCs in ANY.RUN's Interactive Sandbox

What is BTMOB RAT Malware?

BTMOB RAT represents a significant evolution in Android malware, emerging as one of the most sophisticated Remote Access Trojans targeting mobile devices in 2025. This advanced malware evolved from the SpySolr family and has rapidly gained notoriety for its comprehensive data theft capabilities, remote control features, and ability to bypass modern Android security measures. With over 15 variants identified since December 2024, BTMOB RAT poses a serious threat to both individual users and organizations worldwide. The malware operates as a comprehensive Remote Access Trojan specifically designed for Android platforms, leveraging the operating system's Accessibility Service to gain extensive control over infected devices. Unlike traditional mobile malware that focuses on single attack vectors, BTMOB RAT combines multiple techniques including credential theft, remote device control, banking fraud, and data exfiltration capabilities.

What sets BTMOB RAT apart from other mobile threats is its sophisticated use of overlay attacks, particularly targeting financial applications like Alipay. The latest version (v2.5) incorporates advanced obfuscation techniques and can perform real-time screen manipulation.

The malware is distributed through a Malware-as-a-Service (MaaS) model, with cybercriminals advertising lifetime licenses for $5,000 through Telegram channels. This commercial approach has accelerated its adoption among threat actors and contributed to its rapid evolution and widespread distribution.

BTMOB RAT infiltrates via social engineering, primarily phishing sites masquerading as legitimate apps like iNat TV (e.g., tvipguncelpro.com) or fake WhatsApp mods (e.g., WhatsApp GB). Users are tricked into sideloading APKs, which prompt enabling Accessibility Service—framed as necessary for "enhanced features."

Spread occurs through:

  • Phishing Campaigns: URLs distributed on forums, SMS, or search-engine-indexed fake sites (e.g., Argentine tax agency clones).
  • App Stores and Mods: Malicious apps on Google Play or third-party stores.
  • MaaS Distribution: Developers promote via Telegram, enabling affiliates to customize and deploy.

Post-infection, it self-propagates by exfiltrating contacts for SMS phishing or using infected devices to host phishing pages. Geographic targeting, like Morocco's 2025 alerts, shows adaptation to local lures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

BTMOB RAT Malware Victimology

BTMOB RAT predominantly targets Android users in emerging markets with high mobile banking adoption, where digital financial services are rapidly growing but security awareness lags. In Morocco, it has been a focal point of national alerts, affecting smartphone users who enable accessibility features for convenience, leading to widespread banking data theft. Morocco ranks third in Africa for web-based threats, with over 12.6 million attack attempts in 2024, amplifying BTMOB's impact.

Globally, victims include casual users of streaming or mining apps, as well as financial app users in China (e.g., Alipay targets). Recent campaigns have hit Latin America, such as Argentina via fake government sites impersonating tax agencies. Over 500,000 installations of similar accessibility-abusing malware were recorded in 2024, suggesting BTMOB's victim pool could number in the tens of thousands by September 2025. Businesses in retail and finance are indirect victims through employee devices, but primary targets remain individual consumers vulnerable to phishing.

How BTMOB RAT Functions

The trojan operates through several sophisticated mechanisms:

Accessibility Service Abuse:

It exploits Android's Accessibility Service, originally designed to help users with disabilities, to gain broad system permissions and control over user interface elements.

Overlay Attacks:

BTMOB RAT creates transparent or semi-transparent overlays on legitimate applications, particularly banking and payment apps, to capture user credentials and sensitive information without detection.

Remote Administration:

The malware establishes persistent command and control (C&C) communication channels, allowing attackers to remotely execute commands, update malware components, and extract data in real-time.

Dynamic Code Loading:

Advanced variants can download and execute additional malicious modules, expanding their capabilities based on specific attack objectives.

Anti-Detection Techniques:

The malware employs multiple evasion techniques including code obfuscation, runtime application self-protection (RASP), and behavioral analysis evasion to avoid detection by security solutions.

Data Exfiltration:

Stolen information is encrypted and transmitted to attacker-controlled servers through various channels, including HTTPS connections to legitimate-looking domains.

BTMOB RAT Attack Example and Technical Analysis

A dynamic analysis of a BTMOB sample in ANY.RUN’s Interactive Sandbox reveals key operating mechanisms and network activity of the malware.

View analysis

BTMOB RAT analysis in Interactive Sandbox BTMOB RAT sample analysis in the Interactive Sandbox

Network Activity and Encryption

Analysis of network traffic revealed the malware’s attempts to establish a connection with the command and control (C&C) server via hxxx [://] ip/yaarsa/private/yarsap_80541 [.] php. A characteristic sequence of requests is observed: an initial HEAD request, followed by a repeated HEAD after a pause, which is part of the handshake connection establishment mechanism and server availability check.

BTMOB RAT network connection attempts BTMOB RAT sample analysis in the Interactive Sandbox

All commands and data are transmitted through an encrypted channel, which complicates analysis of the payload. To protect its configuration and the collected data, the malware actively uses cryptographic APIs.

BTMOB RAT uses encryption technique Encryption technique used by BTMOB RAT

Configuration File and Management

BTMOB RAT stores its configuration in the system SharedPreferences storage in XML format. The configuration file contains a complex map of boolean values, where each parameter defines the malware's functionality.

BTMOB RAT configuration file in Interactive Sandbox BTMOB RAT configuration file contents visible in Interactive Sandbox

Persistence and Privilege Escalation Mechanisms

Aggressive permission acquisition appears to be the key attack vector. The malware doesn't simply request access but manipulates the interface using Input Injection to automatically press the "Allow" button.

BTMOB RAT uses input injection BTMOB RAT detected to use Input Injection technique

Once access is obtained, it gains control over the device, including implementing the Prevent Application Removal mechanism, intercepting events in Android Settings to block its own uninstallation.

To ensure continuous operation, the malware creates a background service immediately after launch and uses WakeLock, preventing the device from entering sleep mode. Additionally, it checks the lock screen state, which increases its stealth.

Data Collection and Malicious Activity

Before performing its main tasks, the malware conducts comprehensive reconnaissance: collects a list of installed applications, analyzes running processes, and obtains system data. This allows the operator to adapt the attack to the specific device.

Important malicious activity is conducting overlay attacks. The malware overlays phishing windows on legitimate applications, primarily banking and cryptocurrency ones, to steal credentials, PIN codes, and two-factor authentication.

You can view the succession of the above-mentioned processes in ANY.RUN’s Sandbox as a process tree with every behavior’s description.

BTMOB RAT’s malicious processes BTMOB RAT’s malicious processes

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Notable BTMOB RAT Attacks

While specific large-scale BTMOB attacks are still emerging due to its recent discovery, several notable patterns have been identified:

Streaming Service Impersonation Campaigns:

Multiple campaigns have been observed where attackers created sophisticated fake websites mimicking popular streaming platforms, leading to thousands of downloads before detection.

Cryptocurrency Mining Fraud:

Significant campaigns targeting cryptocurrency enthusiasts through fake mining applications have resulted in substantial financial losses and credential theft.

Alipay PIN Theft Operations:

Recent versions specifically targeting Alipay users have demonstrated the malware's evolution toward financial fraud, with overlay attacks successfully capturing payment credentials.

Corporate Device Compromises:

Several incidents have been reported where employee devices were compromised through entertainment-focused phishing, leading to broader organizational security concerns.

These examples demonstrate the malware's versatility and the threat actors' ability to adapt their tactics based on current trends and user interests.

Gathering Threat Intelligence on BTMOB RAT Malware

Threat intelligence plays a crucial role in defending against BTMOB RAT:

  • Proactive Threat Detection: Intelligence feeds provide early warning indicators of new BTMOB RAT campaigns, enabling organizations to implement protective measures before attacks reach their environments.
  • Attribution and Campaign Tracking: Threat intelligence helps identify the tactics, techniques, and procedures (TTPs) used by BTMOB RAT operators, enabling better prediction and prevention of future attacks.
  • Contextual Analysis: Intelligence provides crucial context about BTMOB RAT variants, helping security teams understand the specific threats relevant to their organization and user base.
  • Predictive Security: Advanced threat intelligence can help predict likely evolution paths for BTMOB RAT, enabling proactive security measure implementation.

Start gathering intelligence by searching BTMOB in ANY.RUN’s Threat Intelligence Lookup. View the RAT’s fresh sample analyses to understand TTPs and harvest IOCs:

threatName:"btmob"

BTMOB RAT’s samples found via Threat Intelligence Lookup BTMOB RAT’s samples found via Threat Intelligence Lookup

Threat Intelligence Lookup is available for free: collect indicators, browse sandbox detonations quick and easy.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BTMOB RAT remains a versatile and dangerous remote access Trojan capable of damaging both individuals and enterprises. Its modular architecture, stealthy operations, and adaptability make it a prime tool for cybercriminals and APT actors alike. Proactive defense powered by advanced detection, prevention strategies, and real-time threat intelligence is essential to reduce risks and prevent devastating breaches.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for timely detection and response.

HAVE A LOOK AT

Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More