BTMOB Android malware service generates custom phishing payloads
BTMOB is being sold as a malware-as-a-service kit with a builder for custom Android phishing payloads. ESET says it targets users mainly in Brazil and Latin America.
Intelligence analysis by GPT-5.4 Mini
ESET says BTMOB is a clearweb Android malware service that lets buyers generate tailored phishing payloads without coding. The trojan can steal data, intercept transactions, take screenshots, and abuse Accessibility permissions after installation.
BTMOB is like a bad app factory for criminals. Instead of making one fake app, it helps them quickly build many different ones that look real enough to trick people.
The fake apps can steal information, watch the screen, and help thieves take money while the phone owner is not looking. It is mostly being used in places like Brazil and other parts of Latin America.
The article says the safest habit is to download apps only from the official store and be careful with powerful permissions. Giving a fake app special access is like handing a stranger the keys to a house.
Analysis
What BTMOB is
ESET describes BTMOB as an Android remote access trojan sold as a malware-as-a-service platform. Instead of handing out one fixed malicious app, the operators provide a builder interface that lets customers shape the APK for a specific lure, including which permissions it asks for and what it does after installation.
How it is used
The article says the malware is advertised openly on the clearweb, while sales happen in private Telegram channels. Buyers can pay a monthly fee of $700 or $5,000 for a lifetime license. BTMOB is mostly active in Brazil and Latin America, and it appears to be an evolution of the SpySolr malware family.
Delivery and behavior
ESET says the trojan is spread through phishing sites that pose as streaming services and cryptocurrency mining platforms. Victims are redirected to pages that imitate Google Play and are told to download fake apps. The platform can also generate localized phishing lures so the messaging matches the campaign theme. Once installed, it abuses Android Accessibility Services to gain stronger control and additional permissions without more user action.
Defender takeaways
ESET says it is tracking the threat and updating static detections, but rapid payload generation can weaken single-layer defenses. The practical advice in the article is standard but relevant: install apps only from Google Play, use Play Protect, and revoke powerful permissions like Accessibility when they are not needed.
Key points
- ESET says BTMOB is a malware-as-a-service Android trojan with a builder for custom phishing payloads.
- Customers can choose requested permissions and payload behavior without needing to code.
- The malware is sold in private Telegram channels and advertised on the clearweb.
- ESET says it is mostly active in Brazil and Latin America and is linked to the SpySolr family.
- The article recommends using Google Play, Play Protect, and reviewing Accessibility permissions.



