Tuesday, September 8, 2026

BTMOB Malware Allows Cybercriminals to Remotely Hijack Android Phones

A newly observed Android malware strain, known as BTMOB, is raising concerns among cybersecurity researchers due to its powerful remote access capabilities and ease of deployment.

Initially identified in early 2025, BTMOB has evolved into a full-featured remote access trojan (RAT) that allows attackers to take near-complete control of infected devices.

Unlike traditional banking trojans that focus on stealing financial credentials, BTMOB offers a broader range of malicious functions. Once installed, it can exfiltrate sensitive data, capture screenshots, monitor user activity, and remotely control compromised smartphones.

Fake app store and malicious apps (Source: We Live Security)
Fake app store and malicious apps (Source: We Live Security)

This poses a significant threat not only to individual users but also to organizations that rely on mobile devices for business operations.

BTMOB Malware Remotely Hijack Android Phones

BTMOB is primarily distributed through phishing campaigns. Attackers lure victims to fake websites that impersonate legitimate services such as streaming platforms or cryptocurrency tools.

These sites then redirect users to fraudulent app stores, where they are tricked into downloading malicious APK files. In many cases, these fake stores closely resemble official platforms like Google Play, increasing the likelihood of successful infections.

After installation, the malware abuses Android’s Accessibility Services to gain elevated permissions. This technique enables it to operate with minimal user interaction, granting attackers persistent, stealthy access to the device. By leveraging these permissions, BTMOB can bypass security controls and maintain long-term control over infected systems.

 BTMOB impersonating an Argentine government agency (Source: WeLive Security)
 BTMOB impersonating an Argentine government agency (Source: WeLive Security)

One of the most concerning aspects of BTMOB is its availability as a malware-as-a-service (MaaS) offering. Cybercriminals can purchase the toolkit, which includes a user-friendly APK builder that lets them create customized malicious apps without programming knowledge. This significantly lowers the barrier to entry for less-skilled threat actors.

The malware is actively marketed عبر social media platforms and the open web, often directing potential buyers to Telegram channels for purchase.

Analysts at Welivesecurity said in a report shared with GBHackers that the toolkit costs around $5,000, with additional support fees. However, indications suggest that leaked versions may already be circulating on underground forums, increasing the risk of widespread abuse.

Security researchers have observed region-specific campaigns, including attacks impersonating government agencies to enhance credibility. This adaptability allows attackers to tailor their lures based on geography, improving infection success rates.

Detection remains challenging due to the rapid generation of new variants. Security tools currently identify BTMOB under multiple signatures, including Android/Spy.Agent variants. The malware’s ability to frequently change its payload complicates traditional signature-based detection methods.

To mitigate risks, users and organizations are advised to install apps only from official stores, avoid clicking on unsolicited links, and deploy mobile security solutions. As mobile threats continue to evolve, treating smartphones with the same level of security scrutiny as desktop systems is becoming increasingly critical.

BTMOB highlights the growing sophistication of Android malware and the expanding cybercriminal ecosystem that supports it.

Indicators of compromise

IP addresses

74.125.202.103142.251.183.138173.194.193.138173.194.206.106
178.156.177.192191.101.131.250195.160.221.203104.21.64.137
173.194.194.94191.96.224.87191.96.225.241191.96.78.172
191.96.78.28191.96.79.133191.96.79.179191.96.79.41
192.178.209.95200.9.155.15374.125.132.9578.135.93.123
79.133.57.141arbsniper.com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

Related Articles

Recent News