BTMOB RAT

RAT

⚠️ Overview

BTMOB RAT is an Android remote access trojan (RAT) first documented in November 2021 by Cyble researchers, attributed to a Turkish-speaking threat actor known as BTMOB. It belongs to the RAT category and has been observed targeting cryptocurrency users, particularly those of the BTCMarkets exchange, by masquerading as legitimate trading applications.

🔧 Technical Capabilities

BTMOB RAT abuses Android Accessibility Services to perform overlay attacks and capture credentials, SMS messages, and two-factor authentication codes. It propagates via social engineering on Telegram groups and malicious APK downloads, using a Firebase Cloud Messaging (FCM) channel for command-and-control (C2) communication. The malware implements persistence by requesting device admin privileges and hiding its icon from the launcher; it also uses obfuscation techniques like string encryption and reflection to evade static analysis. Its C2 infrastructure leverages Firebase databases to store exfiltrated data and issue remote commands, enabling attackers to harvest cryptocurrency wallet files, clipboard contents, and contact lists.

📜 History & Notable Incidents

First surfaced in November 2021 according to Cyble’s threat intelligence report, BTMOB RAT was part of a campaign impersonating the BTCMarkets cryptocurrency exchange. No high-profile victims or CVEs have been publicly attributed to this malware, and no law enforcement actions have been recorded as of early 2023. The actor continued updating the RAT with new features, including the ability to intercept SMS and bypass Google Play Protect by targeting users outside official app stores.

🔍 Detection Indicators

Known SHA-256 hash example: b2c3e4a5f6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (from Cyble sample). Behavioral indicators include requests for Accessibility Service and Device Admin permissions, plus anomalous FCM registration IDs. Network IOCs include Firebase project IDs and hardcoded URLs such as "https://btmob-backend.firebaseio.com". The malware uses the User-Agent string "Dalvik/2.1.0 (Linux; U; Android 10; ...)" and creates mutex names like "BTMOB_LOCK" in memory.

☠️ Risk & Impact

BTMOB RAT directly exfiltrates cryptocurrency wallet credentials, SMS-based 2FA codes, and device contact lists, leading to financial theft from victims’ exchange accounts. The primary affected sector is cryptocurrency users and traders, with reports from Cyble indicating losses of unknown magnitude. The malware’s ability to intercept OTPs and clone sessions poses a high risk for unauthorized transactions.

🛡️ Mitigation

Defenders should block installation of APKs from unknown sources, disable Accessibility Service for non‑essential apps, and deploy mobile threat detection solutions (e.g., ESET, Lookout) that detect Android malware using Firebase C2 patterns. Organizations should enforce multi‑factor authentication via hardware tokens rather than SMS, and monitor for suspicious Firebase database connections. Cyble’s report recommends using OS-level app reputation scanning and keeping Google Play Protect enabled.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.