Android Malware & Threats
Android Malware & Threats
Articles on Android-specific malware, including remote access trojans, phishing payloads, and mobile threat actor toolkits.
android malware threatsJun 30, 20268 min
No-Code Android RAT Lets Cybercriminals Build Custom Phishing Payloads for Device Takeover
BTMOB is a malware-as-a-service Android remote access trojan evolved from the SpySolr family, sold with an APK builder that lets buyers generate custom payloads and localized phishing lures without coding. Priced at $5,000 for a lifetime license plus monthly support, the RAT abuses Android Accessibility Services to escalate privileges and exfiltrate data, capture screenshots, record audio, and take full remote control of infected devices. First documented by Cyble in February 2025 and analyzed extensively by ESET in May 2026, BTMOB is primarily active across Brazil and Latin America but poses a growing regional threat.