Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

BTMOB RAT

59
Global rank
38 infographic chevron month
Month rank
48
Week rank

BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

RAT
Type
Unknown
Origin
1 February, 2025
First seen
7 October, 2026
Last seen

How to analyze BTMOB RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 February, 2025
First seen
7 October, 2026
Last seen

IOCs

IP addresses
40.180.127.67
200.9.155.109
216.239.35.12
142.251.150.119
142.251.110.138
216.239.35.4
216.239.35.0
216.239.35.8
54.74.188.50
142.251.13.113
52.30.102.168
142.251.150.120
54.73.172.196
34.241.140.171
142.251.127.81
52.210.44.129
34.104.35.123
142.251.155.119
142.251.157.119
142.251.152.119
Hashes
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
e9c119758419bc448e9277b2df07ccfa25555b99e0991e28047bee73fef2c730
90d05345c471a819a98e1f1217157872d7eb088092123aab24653836b1a99ed8
642fbe6d5c01da00e4d0f03f1b3689b86538beeb5d6eea7dd46101d58c2897e8
b7edf3398bc909660a728e0452de86aa3e2dd6866c4a28f13ddca4e21827c11d
e8bc0f4230a1e2156a731413a8bdf6337012873ecd4895dccc4605bf220ca601
c1d9fb4ed9b36083867ff6f02fa150112754ec5fc06e5eaa69b95baf6a3d40d8
daab4f9e5829127bb4e4a2dcafd2c8ba81c9fed91d787199896996f1fe667a17
c4a57ef3580ee9cc4fe975218f1b8d0c65ee4f37db9b54d43c749e82c3a4bf73
31c9c5858b16a3461dcfe1aae5bf917c130184a6e9efb3866822a8d63916141a
cf8cebf84d67f66096ed284e27ecb7137846cf78d0335b8b1bb634e9f9e3b283
12ed3a4e90dde68d562051c219a4e00dfedf534b9add252cf0603a82ca79838e
5d5ba22b67c29c3b6d4c8f452b0b68e4b38a1ea93c2138e8d96b6c78998af08a
2324a5b63511a638aeb7ee7320ff3e391e5d0e2b3c446f5be7335950e7c93f29
cc210286be41cb89398fa1cfeec3316dff84b3dc3d005326bf40f7c78a17cd12
c4f1e17209b346847cb2deabe72eba4b170b72fc92b3106cdc372b6d5e658e99
31884ca0eb0c1dbbf4f6202f801a76d75d90c518502d2b4fc4249498fa6f2149
9aac045f499544764fb27e3d43ae31147803f2b4e7cb9a48eec26fcaaad2ec35
Domains
checkip.amazonaws.com
edgedl.me.gvt1.com
time.android.com
www.google.com
clientservices.googleapis.com
staging-remoteprovisioning.sandbox.googleapis.com
update.googleapis.com
connectivitycheck.gstatic.com
google.com
www.leroymerlin.com.br
play.googleapis.com
www.chromium.org
m.youtube.com
images-na.ssl-images-amazon.com
4625545.fls.doubleclick.net
developers.google.com
adservice.google.com
www.gstatic.com
freenode.net
googleads.g.doubleclick.net
URLs
http://www.google.com/gen_204
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaborbucxqbilsty5va8cokpo2dujhmdpicgxg=&request_id=5b72127f-dd38-49f9-b81c-b05b4f3262ea
https://update.googleapis.com/service/update2/json?cup2key=15:jjev4vycyuztbozasw5mn8uwuwt5pgm635pugrrv1ce&cup2hreq=9b8322d12d501afc984fcbd22777bb58d65a08fb020bd8a366a258bc021e6245
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://update.googleapis.com/service/update2/json
http://200.9.155.109/yaarsa/private/yarsap_80541.php
http://checkip.amazonaws.com/
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboryubrebilsty615u56nv4mli7bfojfygss=&request_id=646c4a9d-cd86-4c29-9de3-2ef34f01862b
http://191.96.225.176/yaarsa/private/yarsap_80541.php
http://www.leroymerlin.com.br/login
https://www.leroymerlin.com.br/login
https://www.leroymerlin.com.br/favicon.ico
http://play.googleapis.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaborlnseobilstywkcpjwq90vsxriadkiqgpq=&request_id=03cdf2e2-3c34-442f-a88d-5def9b3346a8
https://update.googleapis.com/service/update2/json?cup2key=15:dopxojaqlm_vjzqy4veantr5k5mv3lodkicwag4x7d4&cup2hreq=925b523494b42c3a731a42f8b1fd91c4140f04d11361f94475514d845c9618e7
http://185.241.211.105/yaarsa/private/yarsap_80541.php
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 2547
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 4836
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 7383
comments 0

BTMOB RAT: The Android Phantom Hijacking Your Wallet

Key Takeaways

  1. Commercial-Grade Mobile Malware: BTMOB RAT operates as Malware-as-a-Service with lifetime licenses selling for $5,000, representing a dangerous shift toward professionalized mobile threats with rapid development cycles.
  2. Beyond Traditional Mobile Malware: This isn't just another Android trojan: it combines live screen control, banking overlay attacks, cryptocurrency theft, and comprehensive surveillance capabilities that rival desktop RATs.
  3. Accessibility Service Weaponization: The malware exploits Android's accessibility features designed for disabled users, turning assistive technology into a powerful attack vector that bypasses most traditional mobile security measures.
  4. Financial Services in the Crosshairs: With specialized capabilities targeting Alipay and banking apps through real-time overlay attacks, BTMOB RAT represents a new era of mobile financial fraud that threatens both personal and corporate banking security.
  5. Defense Strategies: Detect via IOCs like specific domains and behavioral anomalies; prevent with app vetting, updates, and MTD tools; leverage threat intelligence for proactive blocking and variant tracking.

BTMOB RAT IOCs in Interactive Sandbox Gather BTMOB RAT IOCs in ANY.RUN's Interactive Sandbox

What is BTMOB RAT Malware?

BTMOB RAT represents a significant evolution in Android malware, emerging as one of the most sophisticated Remote Access Trojans targeting mobile devices in 2025. This advanced malware evolved from the SpySolr family and has rapidly gained notoriety for its comprehensive data theft capabilities, remote control features, and ability to bypass modern Android security measures. With over 15 variants identified since December 2024, BTMOB RAT poses a serious threat to both individual users and organizations worldwide. The malware operates as a comprehensive Remote Access Trojan specifically designed for Android platforms, leveraging the operating system's Accessibility Service to gain extensive control over infected devices. Unlike traditional mobile malware that focuses on single attack vectors, BTMOB RAT combines multiple techniques including credential theft, remote device control, banking fraud, and data exfiltration capabilities.

What sets BTMOB RAT apart from other mobile threats is its sophisticated use of overlay attacks, particularly targeting financial applications like Alipay. The latest version (v2.5) incorporates advanced obfuscation techniques and can perform real-time screen manipulation.

The malware is distributed through a Malware-as-a-Service (MaaS) model, with cybercriminals advertising lifetime licenses for $5,000 through Telegram channels. This commercial approach has accelerated its adoption among threat actors and contributed to its rapid evolution and widespread distribution.

BTMOB RAT infiltrates via social engineering, primarily phishing sites masquerading as legitimate apps like iNat TV (e.g., tvipguncelpro.com) or fake WhatsApp mods (e.g., WhatsApp GB). Users are tricked into sideloading APKs, which prompt enabling Accessibility Service—framed as necessary for "enhanced features."

Spread occurs through:

  • Phishing Campaigns: URLs distributed on forums, SMS, or search-engine-indexed fake sites (e.g., Argentine tax agency clones).
  • App Stores and Mods: Malicious apps on Google Play or third-party stores.
  • MaaS Distribution: Developers promote via Telegram, enabling affiliates to customize and deploy.

Post-infection, it self-propagates by exfiltrating contacts for SMS phishing or using infected devices to host phishing pages. Geographic targeting, like Morocco's 2025 alerts, shows adaptation to local lures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

BTMOB RAT Malware Victimology

BTMOB RAT predominantly targets Android users in emerging markets with high mobile banking adoption, where digital financial services are rapidly growing but security awareness lags. In Morocco, it has been a focal point of national alerts, affecting smartphone users who enable accessibility features for convenience, leading to widespread banking data theft. Morocco ranks third in Africa for web-based threats, with over 12.6 million attack attempts in 2024, amplifying BTMOB's impact.

Globally, victims include casual users of streaming or mining apps, as well as financial app users in China (e.g., Alipay targets). Recent campaigns have hit Latin America, such as Argentina via fake government sites impersonating tax agencies. Over 500,000 installations of similar accessibility-abusing malware were recorded in 2024, suggesting BTMOB's victim pool could number in the tens of thousands by September 2025. Businesses in retail and finance are indirect victims through employee devices, but primary targets remain individual consumers vulnerable to phishing.

How BTMOB RAT Functions

The trojan operates through several sophisticated mechanisms:

Accessibility Service Abuse:

It exploits Android's Accessibility Service, originally designed to help users with disabilities, to gain broad system permissions and control over user interface elements.

Overlay Attacks:

BTMOB RAT creates transparent or semi-transparent overlays on legitimate applications, particularly banking and payment apps, to capture user credentials and sensitive information without detection.

Remote Administration:

The malware establishes persistent command and control (C&C) communication channels, allowing attackers to remotely execute commands, update malware components, and extract data in real-time.

Dynamic Code Loading:

Advanced variants can download and execute additional malicious modules, expanding their capabilities based on specific attack objectives.

Anti-Detection Techniques:

The malware employs multiple evasion techniques including code obfuscation, runtime application self-protection (RASP), and behavioral analysis evasion to avoid detection by security solutions.

Data Exfiltration:

Stolen information is encrypted and transmitted to attacker-controlled servers through various channels, including HTTPS connections to legitimate-looking domains.

BTMOB RAT Attack Example and Technical Analysis

A dynamic analysis of a BTMOB sample in ANY.RUN’s Interactive Sandbox reveals key operating mechanisms and network activity of the malware.

View analysis

BTMOB RAT analysis in Interactive Sandbox BTMOB RAT sample analysis in the Interactive Sandbox

Network Activity and Encryption

Analysis of network traffic revealed the malware’s attempts to establish a connection with the command and control (C&C) server via hxxx [://] ip/yaarsa/private/yarsap_80541 [.] php. A characteristic sequence of requests is observed: an initial HEAD request, followed by a repeated HEAD after a pause, which is part of the handshake connection establishment mechanism and server availability check.

BTMOB RAT network connection attempts BTMOB RAT sample analysis in the Interactive Sandbox

All commands and data are transmitted through an encrypted channel, which complicates analysis of the payload. To protect its configuration and the collected data, the malware actively uses cryptographic APIs.

BTMOB RAT uses encryption technique Encryption technique used by BTMOB RAT

Configuration File and Management

BTMOB RAT stores its configuration in the system SharedPreferences storage in XML format. The configuration file contains a complex map of boolean values, where each parameter defines the malware's functionality.

BTMOB RAT configuration file in Interactive Sandbox BTMOB RAT configuration file contents visible in Interactive Sandbox

Persistence and Privilege Escalation Mechanisms

Aggressive permission acquisition appears to be the key attack vector. The malware doesn't simply request access but manipulates the interface using Input Injection to automatically press the "Allow" button.

BTMOB RAT uses input injection BTMOB RAT detected to use Input Injection technique

Once access is obtained, it gains control over the device, including implementing the Prevent Application Removal mechanism, intercepting events in Android Settings to block its own uninstallation.

To ensure continuous operation, the malware creates a background service immediately after launch and uses WakeLock, preventing the device from entering sleep mode. Additionally, it checks the lock screen state, which increases its stealth.

Data Collection and Malicious Activity

Before performing its main tasks, the malware conducts comprehensive reconnaissance: collects a list of installed applications, analyzes running processes, and obtains system data. This allows the operator to adapt the attack to the specific device.

Important malicious activity is conducting overlay attacks. The malware overlays phishing windows on legitimate applications, primarily banking and cryptocurrency ones, to steal credentials, PIN codes, and two-factor authentication.

You can view the succession of the above-mentioned processes in ANY.RUN’s Sandbox as a process tree with every behavior’s description.

BTMOB RAT’s malicious processes BTMOB RAT’s malicious processes

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Notable BTMOB RAT Attacks

While specific large-scale BTMOB attacks are still emerging due to its recent discovery, several notable patterns have been identified:

Streaming Service Impersonation Campaigns:

Multiple campaigns have been observed where attackers created sophisticated fake websites mimicking popular streaming platforms, leading to thousands of downloads before detection.

Cryptocurrency Mining Fraud:

Significant campaigns targeting cryptocurrency enthusiasts through fake mining applications have resulted in substantial financial losses and credential theft.

Alipay PIN Theft Operations:

Recent versions specifically targeting Alipay users have demonstrated the malware's evolution toward financial fraud, with overlay attacks successfully capturing payment credentials.

Corporate Device Compromises:

Several incidents have been reported where employee devices were compromised through entertainment-focused phishing, leading to broader organizational security concerns.

These examples demonstrate the malware's versatility and the threat actors' ability to adapt their tactics based on current trends and user interests.

Gathering Threat Intelligence on BTMOB RAT Malware

Threat intelligence plays a crucial role in defending against BTMOB RAT:

  • Proactive Threat Detection: Intelligence feeds provide early warning indicators of new BTMOB RAT campaigns, enabling organizations to implement protective measures before attacks reach their environments.
  • Attribution and Campaign Tracking: Threat intelligence helps identify the tactics, techniques, and procedures (TTPs) used by BTMOB RAT operators, enabling better prediction and prevention of future attacks.
  • Contextual Analysis: Intelligence provides crucial context about BTMOB RAT variants, helping security teams understand the specific threats relevant to their organization and user base.
  • Predictive Security: Advanced threat intelligence can help predict likely evolution paths for BTMOB RAT, enabling proactive security measure implementation.

Start gathering intelligence by searching BTMOB in ANY.RUN’s Threat Intelligence Lookup. View the RAT’s fresh sample analyses to understand TTPs and harvest IOCs:

threatName:"btmob"

BTMOB RAT’s samples found via Threat Intelligence Lookup BTMOB RAT’s samples found via Threat Intelligence Lookup

Threat Intelligence Lookup is available for free: collect indicators, browse sandbox detonations quick and easy.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

BTMOB RAT remains a versatile and dangerous remote access Trojan capable of damaging both individuals and enterprises. Its modular architecture, stealthy operations, and adaptability make it a prime tool for cybercriminals and APT actors alike. Proactive defense powered by advanced detection, prevention strategies, and real-time threat intelligence is essential to reduce risks and prevent devastating breaches.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for timely detection and response.

HAVE A LOOK AT

JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Greatness screenshot
Greatness is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals, even those with limited technical skills, to launch sophisticated phishing attacks primarily targeting Microsoft 365 (M365) credentials. It acts as a man-in-the-middle (MitM) proxy, facilitating credential theft and MFA bypass while providing affiliates with easy-to-use tools like attachment builders and Telegram notifications.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More