TF-MAL-apk.btmob
📛 Threat Title
Malware family: BTMOB RAT
Description
ThreatFox malware family `apk.btmob`. Printable name: BTMOB RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.btmob
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.btmob
IOC database
- Type
- domain
- Value
apk.btmob- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.btmob
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.btmob
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
BTMOB RAT is a remote access Trojan ( RAT ) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
-
web:awakewiki.org
BTMOB RAT is an Android remote access trojan sold as Malware -as-a-Service, evolved from the SpySolr malware (itself based on CraxRAT). Cyble Research and Intelligence Labs (CRIL) published the initial analysis on January 31, 2025, after identifying approximately 15 samples of version 2.5 spreading through phishing sites mimicking the Turkish ...
-
web:cyble.com
Cyble analyzes BTMOB RAT , advanced Android malware actively spreading via phishing sites, leveraging Accessibility Services to steal credentials, control devices remotely, and execute various malicious activities.
-
web:github.com
Executive Summary "Customer Support.apk" is a sophisticated Android Remote Access Trojan ( RAT ) / Banking Trojan belonging to the Hook/ERMAC/BankBot malware family . It disguises itself as a legitimate "Customer Support" utility app while secretly providing the attacker with complete remote control over the infected device.
-
web:kandibrian.com
BTMOB V4 is a sophisticated Android RAT sold as Malware -as-a-Service. Learn how it evolved from CraxsRAT through SpySolr, how it works technically, and how to defend against it.
-
web:malpedia.caad.fkie.fraunhofer.de
It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.
-
web:medium.com
Look, I've been reverse-engineering Android crap since the SpyNote days, and most RATs these days are straight garbage — buggy, noisy, and dead in a week. But BTMOB RAT v4.2? This one's ...
-
web:thecyberexpress.com
The malware is designed to exploit Android's Accessibility Services to initiate a range of malicious activities, including remote control, credential theft, data exfiltration, and even device unlocking. What makes Btmob RAT particularly interesting is its seamless integration with WebSocket-based command and control (C&C) communication.
-
web:www.d3lab.net
The structure is not that of a malware kit sold to be deployed independently, but rather a criminal Software-as-a-Service platform. BTMOB RAT Capabilities - A Technical Overview Public research on BTMOB , including analyses by Cyble and Zimperium, describes a malware family defined by its comprehensive abuse of Android's Accessibility Service.
-
web:www.linkedin.com
Morocco's DGSSI has issued an urgent warning about BTMOB RAT , a sophisticated Remote Access Trojan that leverages Android's accessibility services to capture on‑screen banking credentials ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.