Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    6 Windhawk mods that make Windows 11 behave like it should

    June 15, 2026

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 6 Windhawk mods that make Windows 11 behave like it should
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch
    • Chinese Drivers Are Using Tiny Plastic Heads to Fool Tesla’s Autopilot Safeguards
    • 5 new Netflix movies and shows you need to stream this week (June 15-21)
    • Scientists Investigate Strange Rumbling Beneath Utah
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»BTMOB Android malware service generates custom phishing payloads
    Cybersecurity

    BTMOB Android malware service generates custom phishing payloads

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 31, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    BTMOB Android malware service generates custom phishing payloads
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.

    The malware provides a wide set of features that includes stealing specific data, intercepting financial transactions, capturing screenshots, and remote control capabilities.

    Cybersecurity company ESET says that BTMOB is openly advertised on the clearweb and operates as a malware-as-a-service (MaaS) platform. The APK builder included in the offer provides easy customization of the payload without any need to code.

    Customers can select from a set of permissions the APK requests upon installation, and define what actions the app should take (e.g., disable Google Play, hide its icon to make it more difficult to remove from the device, or prevent sleep mode).

    BTMOB’s payload builder
    Source: ESET

    It should be noted that BTMOB is mostly active in Brazil and Latin America. It is not a new Android trojan, as ANYRUN analyzed it in February 2025, and threat intelligence and digital risk protection company Cyble documented it as an advanced Android malware.

    At the time, Cyble spotted about 15 samples of BTMOB 2.5 in nearly two weeks, indicating that the author was actively developing the malware.

    According to ESET researchers, sales are conducted in private Telegram channels. Threat actors can get it with a monthly subscription of $700 monthly subscription, or they can pay $5,000 for a lifetime license.

    BTMOB clearnet site
    Source: ESET

    BTMOB appears to be an evolution of the SpySolr malware family and is distributed via phishing websites masquerading as streaming services and cryptocurrency mining platforms.

    ESET reports that potential victims are redirected to portals mimicking Google Play and prompted to download the fake apps. The

    Researchers Johnk3r and Merl recently spotted BTMOB campaigns that used an Argentinian government agency as a lure.

    Malicious apps on fake Google Play sites
    Source: Merl

    The malware platform also helps operators generate custom, localized phishing lures to match the campaign’s topic. Once installed, it abuses Android Accessibility Services to obtain elevated permissions and additional system access without further user interaction.

    Although ESET is tracking the threat and updates static detection rules accordingly, the rapid generation of new payloads can undermine the effectiveness of single-layered defenses.

    Android users are recommended to install only apps from the official Google Play Store on their phones, scan with Play Protect, and revoke risky and powerful permissions, such as Accessibility access, if not explicitly needed.

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    Android BTMOB custom generates malware payloads Phishing Service
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Proving what a military AI model will do is the real problem

    June 15, 2026

    Phone battery draining fast? Malware is one of 8 possible factors – how to tell for sure

    June 15, 2026

    Laduora Duo 4-in-1 Red Light Therapy Scalp and Hair Care Device Review: Custom Goals

    June 15, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views

    Anthropic’s Mythos AI Uncovered Serious Security Holes in Every Major OS and Browser

    April 10, 20262 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • 6 Windhawk mods that make Windows 11 behave like it should
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch

    6 Windhawk mods that make Windows 11 behave like it should

    June 15, 2026

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026

    Here's what Jeff Bezos' new startup Prometheus will do

    June 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.