RAT
BTMOB RAT
According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration.
According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration. It spreads via phishing sites impersonating streaming services like iNat TV and fake mining platforms. The malware abuses Android’s Accessibility Service to unlock devices, log keystrokes, and automate credential theft through injections. It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.
Family metadata imported from Malpedia (Fraunhofer FKIE).