BTMOB Android spyware splinters into a messy resale market

What started as a single Android remote-access tool for hire has fractured into resellers, source-code buyers and impersonators trading under the same name.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened smartphone screen displaying a generic green messenger app with a QR code prompt, faint Cyr
Share

Key points

  • BTMOB, an Android remote access trojan sold as a service since early 2025, has fragmented into a wider market of resellers, private server operators and source-code buyers.
  • The original operator sold the full source code for $20,000 in May 2025, then dropped the price to $10,000 later that year.
  • A coordinated Telegram campaign advertised BTMOB V4.1.2 and V4.2 lifetime access for $500, with claimed source code at $1,500.
  • On April 26 the main BTMOB channel warned that only one account was official and denied ties to other sellers using the name.
  • The official operation released V4.5 in April 2026, offering a $1,200 lifetime account, a $3,000 private server, or server source code for $7,000.

A piece of Android spyware sold on criminal forums has quietly turned into a small, messy industry, and its original creator appears to be losing control of it.

The malware is called BTMOB. It is an Android remote access trojan, meaning malicious software that hides inside a phone app and lets a criminal read messages, steal passwords and control the device from afar. Researchers at threat intelligence firm Flare, whose findings were first reported by BleepingComputer, tracked thousands of underground forum and Telegram posts about it from early 2025 onward.

What they found is a criminal product behaving a lot like a legitimate one that leaked. Cheaper knockoffs. Rival support channels. Accounts claiming to be the real seller. The BTMOB name now travels far beyond whoever built it.

What is BTMOB, in plain terms?

BTMOB is a ready-made toolkit for infecting Android phones. Buyers get a builder that wraps the spyware inside a normal-looking app, a Windows control panel to manage infected devices, server infrastructure, and phishing tools for stealing banking logins.

That bundle is the appeal. A buyer with modest skills can run an Android spying operation without writing a line of code. Depending on the tier, they also get hosted servers and technical support, much like a software company would offer.

Flare has not published the malware to a specific named cluster in vendor taxonomies such as those used by Google or Zimperium, and attribution of the operators behind BTMOB remains thin. Treat everything below as tracked activity, not confirmed identity.

How did one product become a whole market?

It started with money problems and a big decision to sell the recipe. In January 2025 the official channel priced BTMOB V2 at $700 a month or $3,000 for lifetime access. Within weeks the operator was publicly complaining about server errors, saying more than 4,000 phones were connected but he could not tell real customer traffic from a denial-of-service attack against his own infrastructure.

In May 2025 the channel put the full source code up for sale at $20,000. That package included the PHP and Node.js server components, the VB.NET operator panel, and the Java code for the Android implant. The operator argued the sale would fund development and let buyers audit the code.

Things frayed from there. A Spanish and Portuguese support channel went offline during a dispute with two former administrators. In July, the main channel said its admins would go independent and take their own customers with them. A Brazilian administrator reportedly bought the source and began running a separate fork. The advertised source price later fell to $10,000.

What are the copycats selling?

Cheap access, and a lot of it. A coordinated Telegram push offered BTMOB V4.1.2 and V4.2 lifetime access for $500, with claimed "RAT and server file source code" at $1,500. The same wording appeared across multiple channels pointing to handles like @thebtmobadmin and @btmobportal.

On April 26 the main channel pushed back, insisting it had only one official outlet and warning about impersonators. Whether that warning referred to the $500 sellers specifically is unclear.

Version Date Headline offer
V2 Jan 2025 $700/month, $3,000 lifetime
Source code May 2025 $20,000 full package
V4 Dec 2025 Lifetime + private servers
V4.5 Apr 2026 $1,200 lifetime, $7,000 server source

Other sellers went lower still, offering weekly plans, custom branding, and free trials. Some of those files are probably genuine forks. Others are almost certainly repackaged junk or outright scams aimed at other criminals.

Should ordinary phone users worry?

Yes, but in the same way you already should. BTMOB and its clones spread through fake apps, side-loaded installs, and phishing links, not through the official Google Play store in most cases. Stick to Play, do not install Android apps from links sent by strangers, and be wary of any app that immediately asks for accessibility permissions. That single permission is what lets this kind of spyware read your screen and type on your behalf.

© 2026 Threat Vectr