惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
MyScale Blog
MyScale Blog
有赞技术团队
有赞技术团队
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
Vercel News
Vercel News
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
美团技术团队
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
A
About on SuperTechFans
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
宝玉的分享
宝玉的分享
V
V2EX
Microsoft Azure Blog
Microsoft Azure Blog

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
BTMOB RAT Gives Criminals a Point-and-Click Kit to Take O...
Pierluigi Paganini · 2026-05-29 · via Security Affairs

BTMOB sells Android full-device takeover as a kit, no coding needed. It steals data, records screens, and hands attackers remote control for $5,000 lifetime.

Most Android malware requires at least some technical competence to deploy, but the BTMOB doesn’t. The developers sell it with a built-in APK builder that lets buyers generate new malicious apps, swap phishing lures, and target different countries without writing a single line of code. That’s the part worth paying attention to.

ESET researcher Daniel Cunha Barbosa flagged BTMOB while reviewing threat detections in Brazil. It’s been around since at least early 2025, evolving from an older piece of malware called SpySolr, and it’s been picked up fast. The Android malware BTMOB is a full takeover.

“Unlike banking trojans, which “only” aim to steal people’s financial credentials or intercept their financial transactions, BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it.” reads the report published by ESET. “The RAT is also sold with an APK builder interface, allowing anyone to generate new payloads and adapt phishing lures for specific regions at a rapid clip – and without writing any code.”

The infection starts with a phishing message pointing victims to a fake website impersonating a streaming service, a crypto mining platform, or something similarly familiar. That site redirects victims to a fake app store that looks like Google Play and prompts them to install an APK. Once the APK is installed on the device, BTMOB abuses Android Accessibility Services to grant itself elevated permissions without any further user input. No second tap required.

The business model is worth examining. A lifetime license costs $5,000 plus a monthly support fee, low compared to what a successful fraud operation returns.

“Since it’s built for the malware-as-a-service (MaaS) economy, BTMOB is marketed as a software product, including through a promotional page on the open web that funnels prospective buyers to a Telegram operator. The sales pipeline extends across social media platforms, with a number of accounts on X and Instagram actively peddling the tool.” continues the report. “Once someone purchases the malicious kit, they can adapt its features, including the phishing lures so they impersonate the brand or agency most likely to lure victims in any given country.

Researchers have already observed campaigns in Argentina impersonating the country’s tax and customs authority, AFIP. The kit makes that kind of localization trivial.

Distribution runs through an open web page linking to a Telegram channel, with active promotional accounts on X and Instagram. The researchers pointed out that there isn’t a dark web operation; it’s more like a SaaS vendor with a slightly unusual product category.

In January 2026, files related to BTMOB briefly appeared for free on a dark web forum before it went offline. ESET couldn’t recover the payloads, but the episode illustrates a pattern familiar with commercial malware: ‘access rarely stays contained forever and the tool can move into secondary markets through resale, barter or sharing inside closed groups.’

Once a toolkit like this leaks, the pool of people who can cause damage with it expands fast. Researchers warn that leaked or resold versions could spread quickly across underground markets. Because criminals can rapidly generate new variants, defenders face constant payload changes instead of a stable threat. Security firms have already identified multiple new BTMOB samples and related Android spyware variants appearing within short periods of time.

Detection names include Android/Spy.Agent.EIJ, Android/Spy.Agent.EIK, and MSIL/BtmobRat for the primary tool. A full list of indicators including IP addresses and SHA256 hashes is published in ESET’s report.

Most of the confirmed activity so far has been in Latin America, but the kit’s customization features make regional containment a poor assumption. Any Android user who installs apps from outside official stores, clicks unsolicited links in messaging apps, or ignores security software on their phone is a viable target. The practical defense is unglamorous but solid: only install apps from Google Play, treat every unsolicited link as hostile, and run a mobile security solution. The people selling BTMOB are counting on you not to bother.

The report includes Indicators of compromise (IoCs).

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Android Malware)