Skip to content

RAT

BTMOB RAT

According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration.

BTMOB RAT is a Android rat.

Background

Cyble characterizes BTMOB RAT as a sophisticated Android threat descended from SpySolr, providing remote control, credential harvesting, and data exfiltration. Distribution relies on phishing pages that mimic streaming services such as iNat TV as well as bogus mining platforms. The RAT leverages Android's Accessibility Service to unlock handsets, capture keystrokes, and automate the theft of credentials through injection routines. Command-and-control runs over WebSocket connections, enabling real-time command execution and data theft, and the malware can perform actions including live screen sharing, file management, audio recording, and web injections.


Source: Malpedia (Fraunhofer FKIE).