{"id":222972,"date":"2026-05-31T02:25:05","date_gmt":"2026-05-31T06:25:05","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/31\/new-btmob-android-malware-enables-full-device-takeover-2\/"},"modified":"2026-05-31T02:25:08","modified_gmt":"2026-05-31T06:25:08","slug":"new-btmob-android-malware-enables-full-device-takeover-2","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/31\/new-btmob-android-malware-enables-full-device-takeover-2\/","title":{"rendered":"New BTMOB Android Malware Enables Full Device Takeover"},"content":{"rendered":"<p><a href=\"https:\/\/www.securityweek.com\/new-btmob-android-malware-enables-full-device-takeover\/\">New BTMOB Android Malware Enables Full Device Takeover<\/a><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/new-btmob-android-malware-enables-full-device-takeover\/\">https:\/\/www.securityweek.com\/new-btmob-android-malware-enables-full-device-takeover\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-28 09:05:04<\/a><\/p>\n<p>Source Domain: <a href=\"www.securityweek.com\">www.securityweek.com<\/a><\/p>\n<p><strong>Summary<\/strong><\/p>\n<p>ESET has highlighted that the BTMOB remote access trojan (RAT) poses a significant threat to Android users due to its ability to steal data and gain control over devices. The malware, believed to be derivated from SpySolr, is distributed primarily through phishing tactics that appeal to streaming or cryptocurrency services. Its creators sell it alongside an APK builder toolkit, enabling even non-coders to customize phishing lures tailored to specific geographic targets. The BTMOB kit is sold for $5,000 with monthly support, although a dark web version was briefly available for free. When installed, the RAT leverages Android\u2019s Accessibility Services to inflate its privileges without user knowledge, leading to extensive data theft, screenshot capturing, and device control. Notably, ESET observes a rapid evolution of the RAT with frequent variants, yet certain infrastructure elements remain unchanged. While primarily active in Latin America, ESET maintains that the broader threat transcends this region.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>BTMOB is a major threat to Android users, capable of data exfiltration, device control, and screenshot capture.<\/li>\n<li>The malware is distributed via phishing attacks tailored through a kit that allows users to create customized payloads.<\/li>\n<li>BTMOB targets users with a lifetime &#8211; The generated text has been blocked by our content filters.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New BTMOB Android Malware Enables Full Device Takeover https:\/\/www.securityweek.com\/new-btmob-android-malware-enables-full-device-takeover\/ Publish Date: 2026-05-28 09:05:04 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":222974,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.securityweek.com\/wp-content\/uploads\/2025\/02\/Android-update.jpeg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32,25],"class_list":["post-222972","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222972"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=222972"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222972\/revisions"}],"predecessor-version":[{"id":222976,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222972\/revisions\/222976"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/222974"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=222972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=222972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=222972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}