Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Paratrix.XYZ Collaborates With AdaptHF To Optimize Tokenized Asset Management With AI

May 26, 2026

Chainlink whale wallets hit record highs! Will LINK’s rally continue?

May 26, 2026

Crypto-Backed Super PACs in Focus as Lawmakers Push $5,000 Donation Cap

May 26, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»BTMOB Android RAT Spreads Through No-Code Builder Tooling
BTMOB Android RAT Spreads Through No-Code Builder Tooling
Security and Privacy

BTMOB Android RAT Spreads Through No-Code Builder Tooling

May 26, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

An Android remote access trojan (RAT) that lets buyers build their own custom payloads without writing a line of code has been observed spreading through phishing campaigns across Brazil and beyond.

According to new analysis from ESET, the malware, known as BTMOB, pairs phishing-based delivery with a packaged app-building tool and full device takeover.

First documented in February 2025, BTMOB evolved from the earlier SpySolr family and extends beyond a typical banking trojan. Rather than only chasing financial credentials, it can exfiltrate data, capture screenshots, record on-device activity and hand operators remote control of the phone.

Sold as a Product, Built Without Code

What sets BTMOB apart, however, is its commercial packaging. The RAT ships with an APK builder interface that lets buyers quickly generate new payloads and retool phishing lures for specific countries, with no coding required.

Distribution follows a familiar social-engineering pattern. Operators steer victims to phishing sites posing as streaming services, crypto-mining platforms or other recognizable brands, then funnel them toward fake app stores that prompt installation of a malicious APK.

Once on the device, BTMOB abuses Android’s Accessibility Services to escalate its own permissions and grant itself deeper system access without further user interaction.

Researchers have already seen the kit adapted to impersonate local institutions, including campaigns spoofing Argentina’s tax and customs authorities.

Read more on Android MaaS threats: New Android Albiriox Malware Gains Traction in Dark Web Markets

Cheap Licenses, Fast Mutation

BTMOB is sold through a malware-as-a-service (MaaS) model, marketed on a surface-web promotional page that channels buyers to a Telegram operator, alongside seller accounts on X and Instagram.

See also  Ethereum Attestation Service Launches Innovative Builder Program

ESET said a reported $5,000 lifetime license plus a monthly support fee is modestly set against the proceeds of a successful fraud operation, and the service model lowers the bar for less skilled criminals.

That economic logic also makes containment hard. In January 2026, a dark web forum briefly advertised BTMOB files for free before going offline, a reminder that commercial malware rarely stays locked to paying customers once resale and sharing take hold.

Because new variants can be spun up so quickly, ESET warned defenders to expect rapid payload turnover rather than a fixed set of samples.

The company advised users to install apps only from official stores, treat unsolicited links with suspicion and run mobile security software with the same rigor applied to other devices.

“Corporate security teams must make it clear to employees that a single rogue download could expose the company’s crown jewels,” ESET concluded.

Source link

Android BTMOB Builder NoCode RAT Spreads Tooling
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The Massive Supply Chain Attack Targeting Crypto Developers

May 26, 2026

Parallel TCG Drops Game Manual 1.0 and Cheat Sheet as Card Battler Goes Live Across Epic, Steam, iOS, and Android

May 23, 2026

Polymarket Suffers $700K Breach After Internal Admin Wallet is Compromised

May 22, 2026

Echo Protocol Pauses Monad Bridge After Admin Key Breach Sparks $816K Loss

May 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Mining Milestone: Bitcoin’s Hashrate Soars to Unprecedented Heights in the New Year

January 3, 2025

Coinbase files motion to dismiss SEC lawsuit in its ‘entirety’

August 5, 2023

Kinetix eyes GMX’s path, aims to revolutionize Kava Chain with perpetual swaps

August 31, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Paratrix.XYZ Collaborates With AdaptHF To Optimize Tokenized Asset Management With AI

May 26, 2026

Chainlink whale wallets hit record highs! Will LINK’s rally continue?

May 26, 2026

Crypto-Backed Super PACs in Focus as Lawmakers Push $5,000 Donation Cap

May 26, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$75,927.00-1.74%
  • ethereumEthereum(ETH)$2,074.12-1.71%
  • tetherTether(USDT)$1.00-0.04%
  • binancecoinBNB(BNB)$656.20-0.79%
  • rippleXRP(XRP)$1.33-1.75%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$83.73-1.97%
  • tronTRON(TRX)$0.3744680.85%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.08%
  • dogecoinDogecoin(DOGE)$0.101043-1.30%