Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026

    Gen1 Makes It Easy To Capture GrandParents Stories – Know Your Family History – NextBigFuture.com

    September 11, 2026

    Best SIM-only Deals September 2026: Plans for all budgets

    September 11, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»New BTMOB Android Malware Enables Full Device Takeover
    New BTMOB Android Malware Enables Full Device Takeover
    Cybersecurity

    New BTMOB Android Malware Enables Full Device Takeover

    The Tech GuyBy The Tech GuyMay 28, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The BTMOB remote access trojan (RAT) is becoming a heightened threat to Android users due to its data theft and device takeover capabilities, ESET warns.

    Advertisement

    Believed to be based on the SpySolr malware, BTMOB is distributed via phishing attacks leveraging lures such as streaming, cryptocurrency mining, and other familiar services.

    Its developers, however, sell it bundled with an APK builder interface, allowing threat actors to tailor lures and create new payloads based on their target geographies, without writing code.

    “Once someone purchases the malicious kit, they can adapt its features, including the phishing lures so they impersonate the brand or agency most likely to lure victims in any given country,” ESET notes.

    The malware is promoted via an open web page linking to a Telegram channel. Social media accounts on X and Instagram are also used to promote the Android malware.

    BTMOB is offered for a lifetime license for $5,000, along with a monthly support fee. In January 2026, files related to the RAT were offered for free on a dark web forum that went offline.

    Advertisement. Scroll to continue reading.

    Threat actors have been observed delivering phishing messages that point victims to websites posing as legitimate services, which redirect to fake application stores mimicking legitimate repositories and serving the malicious APK.

    Once executed on a device, BTMOB attempts to obtain excessive access, abusing Android Accessibility Services to elevate its privileges on the system without user interaction.

    “Unlike banking trojans, which ‘only’ aim to steal people’s financial credentials or intercept their financial transactions, BTMOB gives adversaries broader options: exfiltrate a range of sensitive data, capture screenshots and record activity on the device, and ultimately take remote control of it,” ESET says.

    The cybersecurity firm notes that the malware is mutating quickly, with numerous variants being observed within a short period of time, but that certain infrastructure patterns remained unmodified across iterations.

    BTMOB has been mainly observed in attacks in Latin America, but the risk it poses stretches beyond the region, ESET warns.

    Related: Critical Remote Code Execution Vulnerability Patched in Android

    Related: Mirax RAT Targeting Android Users in Europe

    Related: PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

    Related:New Keenadu Android Malware Found on Thousands of Devices

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026

    Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

    September 11, 2026

    Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

    September 11, 2026

    Mandiant Founder Kevin Mandia Joins Amazon Board

    September 10, 2026

    Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    September 10, 2026

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026

    Gen1 Makes It Easy To Capture GrandParents Stories – Know Your Family History – NextBigFuture.com

    September 11, 2026

    Best SIM-only Deals September 2026: Plans for all budgets

    September 11, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.