s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-apk.btmob

📛 Threat Title

Malware family: BTMOB RAT

Category: BTMOB RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.btmob`. Printable name: BTMOB RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.btmob VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.btmob

IOC database

Type
domain
Value
apk.btmob
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.btmob

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.btmob

References (1)

Remediations (10)

  • web:any.run

    BTMOB RAT is a remote access Trojan ( RAT ) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

  • web:awakewiki.org

    BTMOB RAT is an Android remote access trojan sold as Malware -as-a-Service, evolved from the SpySolr malware (itself based on CraxRAT). Cyble Research and Intelligence Labs (CRIL) published the initial analysis on January 31, 2025, after identifying approximately 15 samples of version 2.5 spreading through phishing sites mimicking the Turkish ...

  • web:cyble.com

    Cyble analyzes BTMOB RAT , advanced Android malware actively spreading via phishing sites, leveraging Accessibility Services to steal credentials, control devices remotely, and execute various malicious activities.

  • web:github.com

    Executive Summary "Customer Support.apk" is a sophisticated Android Remote Access Trojan ( RAT ) / Banking Trojan belonging to the Hook/ERMAC/BankBot malware family . It disguises itself as a legitimate "Customer Support" utility app while secretly providing the attacker with complete remote control over the infected device.

  • web:kandibrian.com

    BTMOB V4 is a sophisticated Android RAT sold as Malware -as-a-Service. Learn how it evolved from CraxsRAT through SpySolr, how it works technically, and how to defend against it.

  • web:malpedia.caad.fkie.fraunhofer.de

    It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.

  • web:medium.com

    Look, I've been reverse-engineering Android crap since the SpyNote days, and most RATs these days are straight garbage — buggy, noisy, and dead in a week. But BTMOB RAT v4.2? This one's ...

  • web:thecyberexpress.com

    The malware is designed to exploit Android's Accessibility Services to initiate a range of malicious activities, including remote control, credential theft, data exfiltration, and even device unlocking. What makes Btmob RAT particularly interesting is its seamless integration with WebSocket-based command and control (C&C) communication.

  • web:www.d3lab.net

    The structure is not that of a malware kit sold to be deployed independently, but rather a criminal Software-as-a-Service platform. BTMOB RAT Capabilities - A Technical Overview Public research on BTMOB , including analyses by Cyble and Zimperium, describes a malware family defined by its comprehensive abuse of Android's Accessibility Service.

  • web:www.linkedin.com

    Morocco's DGSSI has issued an urgent warning about BTMOB RAT , a sophisticated Remote Access Trojan that leverages Android's accessibility services to capture on‑screen banking credentials ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.