BTMOB, an Android remote access trojan (RAT) operating as a malware-as-a-service (MaaS) platform, has seen its underground market fragment into competing resellers and impersonators. Originally launched in early 2025, the service allows cybercriminals to generate custom phishing payloads and steal sensitive data, primarily targeting users in Brazil and Latin America.
The cybercrime economy is shifting from lone hackers to commercialized software models. BTMOB exemplifies this trend, evolving from a centralized operation into a chaotic ecosystem of independent server operators and alleged source-code owners. While the original developers still promote new versions, the market has fragmented into a mix of legitimate-looking vendors and fake sellers.
BTMOB’s Pricing and MaaS Infrastructure
BTMOB functions as a professional SaaS company, offering a toolkit that removes the need for buyers to write their own code. According to ESET, the platform is openly advertised on the clearweb and sold through private Telegram channels. The service provides an APK builder that allows customers to customize payloads, select requested permissions, and define actions such as disabling Google Play or hiding the app icon.
The financial structure of the operation was designed for premium access.
| Package Type | Estimated Cost |
|---|---|
| Monthly Subscription | Around $700 |
| Lifetime License | Approximately $3,000 |
| Private Infrastructure Package | Around $5,000 plus recurring payments |
This infrastructure provides buyers with Windows-based administration panels, command-and-control servers, and credential theft tools. The malware typically spreads through phishing sites masquerading as cryptocurrency mining platforms or streaming services. Victims are often redirected to fake Google Play portals to download the malicious apps.
The $20,000 Source Code Sale and Market Decay
A critical turning point occurred in May 2025 when the operators allegedly began selling the complete BTMOB source code. This package, which carried an asking price of approximately $20,000, included Java Android malware code, PHP and Node.js server components, and a VB.NET control panel.
While the operator intended to create additional revenue, the move effectively destroyed their monopoly. Once the code entered the wild, competitors and modified versions emerged. This instability was compounded by internal disputes; a Spanish and Portuguese support channel reported temporary service interruptions following conflicts between administrators, who accused former members of damaging operations.
Operational failures also plagued the group. Shortly after launch, operators admitted to server problems, though they could not confirm if the traffic was legitimate customer activity or a denial-of-service attack. These engineering hurdles mirror the challenges faced by legal software companies, proving that scaling a criminal enterprise requires the same backend reliability as any legitimate tech firm.
Technical Capabilities and Regional Targeting
BTMOB is an evolution of the SpySolr malware family. It is designed to grant attackers full remote control over infected smartphones, including the ability to capture screenshots and intercept financial transactions. To achieve this, the malware abuses Android Accessibility Services to gain elevated system access without further user interaction.
The threat is most concentrated in Brazil and Latin America. Recent campaigns identified by researchers Johnk3r and Merl utilized an Argentinian government agency as a phishing lure to trick users into installing the trojan. The platform’s ability to generate localized lures allows attackers to quickly pivot their targeting to match specific regional topics.
Detection remains a challenge because the builder allows for the rapid generation of new payloads. ESET notes that this agility can undermine single-layered defenses, as static detection rules must be constantly updated to keep pace with the custom versions being churned out by the MaaS platform.
Android Defense and Permission Risks
Because BTMOB relies on social engineering and the abuse of system permissions, security researchers emphasize the danger of “powerful” permissions. Specifically, Accessibility access is a primary vector that BTMOB uses to bypass user interaction and seize control of the device.

- Install applications exclusively from the official Google Play Store.
- Regularly scan devices using Google Play Protect.
- Revoke risky permissions, particularly Accessibility access, if they are not explicitly required for the app’s core function.
While the original BTMOB empire may be fragmenting, the availability of its source code ensures that derivatives of the trojan will likely persist in the wild, distributed by the very resellers and impersonators who contributed to the original operation’s collapse.
Discover more from Archyworldys
Subscribe to get the latest posts sent to your email.