Malware

BTMOB RAT

According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration. It spreads via phishing sites impersonating streaming services like iNat TV and fake mining platforms. The malware abuses Android’s Accessibility Service to unlock devices, log keystrokes, and automate credential theft through injections. It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.

Indicators of Compromise 35

MITRE ATT&CK TTPs 1

Source Articles

Inside the Underground Business of BTMOB RAT
BTMOB is an Android remote access trojan (RAT) offered as malware-as-a-service (MaaS), enabling attackers to steal data and remotely control infected devices. Initially operated as a centralized service, BTMOB's ecosystem has fragmented after the original operator sold the full source code in 2025, leading to independent resellers, counterfeit versions, and impersonators. The official operation continues to release new versions and sell access, private infrastructure, and source code, while cheaper alternatives have emerged on Telegram and underground forums, creating a decentralized and untrustworthy marketplace. This proliferation complicates attribution and increases the risk of scams and unstable or malicious variants.
bleeping-computer ·4w ago
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
The article details the discovery and analysis of a malicious Android Remote Access Tool (RAT) framework called Flying Eagle, which was leaked in early 2026 and has since been widely distributed by cybercriminal actors. The malware is distributed via fake apps impersonating Chinese government services and includes capabilities for credential theft, keylogging, screen capture, and phishing overlays. At least 170 active servers hosting the Flying Eagle infrastructure were identified, primarily in Hong Kong, using shared codebases and panel fingerprints. A new successor platform named Night Dragon has emerged, developed by the threat actor behind the @SQLRCE0 Telegram channel, indicating ongoing evolution of this mobile threat ecosystem.
static-urls