Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Turning Tech Talent Into Leadership Legacy

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech
    • The AI ‘Slowdown’ Is an Antitrust Mess
    • The Next Frontier Is Not Artificial Intelligence—It’s Artificial Societies
    • Here’s What the AI Apocalypse Could Look Like
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»BTMOB Android malware service generates custom phishing payloads
    Cybersecurity

    BTMOB Android malware service generates custom phishing payloads

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 31, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    BTMOB Android malware service generates custom phishing payloads
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.

    The malware provides a wide set of features that includes stealing specific data, intercepting financial transactions, capturing screenshots, and remote control capabilities.

    Cybersecurity company ESET says that BTMOB is openly advertised on the clearweb and operates as a malware-as-a-service (MaaS) platform. The APK builder included in the offer provides easy customization of the payload without any need to code.

    Customers can select from a set of permissions the APK requests upon installation, and define what actions the app should take (e.g., disable Google Play, hide its icon to make it more difficult to remove from the device, or prevent sleep mode).

    BTMOB’s payload builder
    Source: ESET

    It should be noted that BTMOB is mostly active in Brazil and Latin America. It is not a new Android trojan, as ANYRUN analyzed it in February 2025, and threat intelligence and digital risk protection company Cyble documented it as an advanced Android malware.

    At the time, Cyble spotted about 15 samples of BTMOB 2.5 in nearly two weeks, indicating that the author was actively developing the malware.

    According to ESET researchers, sales are conducted in private Telegram channels. Threat actors can get it with a monthly subscription of $700 monthly subscription, or they can pay $5,000 for a lifetime license.

    BTMOB clearnet site
    Source: ESET

    BTMOB appears to be an evolution of the SpySolr malware family and is distributed via phishing websites masquerading as streaming services and cryptocurrency mining platforms.

    ESET reports that potential victims are redirected to portals mimicking Google Play and prompted to download the fake apps. The

    Researchers Johnk3r and Merl recently spotted BTMOB campaigns that used an Argentinian government agency as a lure.

    Malicious apps on fake Google Play sites
    Source: Merl

    The malware platform also helps operators generate custom, localized phishing lures to match the campaign’s topic. Once installed, it abuses Android Accessibility Services to obtain elevated permissions and additional system access without further user interaction.

    Although ESET is tracking the threat and updates static detection rules accordingly, the rapid generation of new payloads can undermine the effectiveness of single-layered defenses.

    Android users are recommended to install only apps from the official Google Play Store on their phones, scan with Play Protect, and revoke risky and powerful permissions, such as Accessibility access, if not explicitly needed.

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    Android BTMOB custom generates malware payloads Phishing Service
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    September 15, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech

    Turning Tech Talent Into Leadership Legacy

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026

    The Leftist Split Over AI Doom

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.