ProBackend
Android Malware & Threats

Android Malware & Threats

Articles on Android-specific malware, including remote access trojans, phishing payloads, and mobile threat actor toolkits.

android malware threatsJun 30, 20268 min

No-Code Android RAT Lets Cybercriminals Build Custom Phishing Payloads for Device Takeover

BTMOB is a malware-as-a-service Android remote access trojan evolved from the SpySolr family, sold with an APK builder that lets buyers generate custom payloads and localized phishing lures without coding. Priced at $5,000 for a lifetime license plus monthly support, the RAT abuses Android Accessibility Services to escalate privileges and exfiltrate data, capture screenshots, record audio, and take full remote control of infected devices. First documented by Cyble in February 2025 and analyzed extensively by ESET in May 2026, BTMOB is primarily active across Brazil and Latin America but poses a growing regional threat.