# BTMOB: A stealthy RAT burrowing deep into Android devices

DevFeed: [BTMOB: A stealthy RAT burrowing deep into Android devices](<https://devfeed.tech/articles/btmob-a-stealthy-rat-burrowing-deep-into-android-devices-8390.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/>)

Author: Daniel Cunha Barbosa

Published: 2026-05-26T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Android](<https://devfeed.tech/topics/android.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>)

## AI overview

BTMOB is an Android remote access trojan that spreads through phishing websites, fake app stores, and malicious APKs. It can exfiltrate sensitive data, capture screenshots, record device activity, and enable remote control. Its APK builder and malware-as-a-service model make customized campaigns easier to launch.

## Source excerpt

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise