BTMOB Android spyware splinters into a messy resale market
What started as a single Android remote-access tool for hire has fractured into resellers, source-code buyers and impersonators trading under the same name.

Key points
- BTMOB, an Android remote access trojan sold as a service since early 2025, has fragmented into a wider market of resellers, private server operators and source-code buyers.
- The original operator sold the full source code for $20,000 in May 2025, then dropped the price to $10,000 later that year.
- A coordinated Telegram campaign advertised BTMOB V4.1.2 and V4.2 lifetime access for $500, with claimed source code at $1,500.
- On April 26 the main BTMOB channel warned that only one account was official and denied ties to other sellers using the name.
- The official operation released V4.5 in April 2026, offering a $1,200 lifetime account, a $3,000 private server, or server source code for $7,000.
A piece of Android spyware sold on criminal forums has quietly turned into a small industry that its original creator appears to be losing control of.
The malware is called BTMOB. It's an Android remote access trojan, meaning malicious software that hides inside a phone app and lets a criminal read messages, steal passwords or control the device from afar. Researchers at threat intelligence firm Flare, whose findings were first reported by BleepingComputer, tracked thousands of underground forum and Telegram posts about it from early 2025 onward.
What they found is a criminal product behaving a lot like a legitimate one that leaked. Cheaper knockoffs. Rival support channels. Accounts claiming to be the real seller. The BTMOB name now travels far beyond whoever built it. It's a pattern we've tracked across the malware-as-a-service space; our report on RedWing from 7 July showed a nearly identical franchise dynamic playing out with a competing Android kit.
What is BTMOB, in plain terms?
BTMOB is a ready-made toolkit for infecting Android phones. Buyers get a builder that wraps the spyware inside a normal-looking app, a Windows control panel to manage infected devices and server infrastructure, plus phishing tools for stealing banking logins.
That bundle is the appeal. A buyer with modest skills can run an Android spying operation without writing a line of code. Depending on the tier, they also get hosted servers and technical support, much like a software company would offer.
Flare hasn't published attribution to a specific named cluster in vendor taxonomies, and the identities of the operators behind BTMOB remain thin. Treat everything below as tracked activity, not confirmed identity.
How did one product become a whole market?
It started with money problems and a decision to sell the recipe. In January 2025 the official channel priced BTMOB V2 at $700 a month or $3,000 for lifetime access. Within weeks the operator was publicly complaining about server errors, saying more than 4,000 phones were connected but he couldn't tell real customer traffic from a denial-of-service attack against his own infrastructure.
In May 2025 the channel put the full source code up for sale at $20,000. That package included the PHP and Node.js server components, the VB.NET operator panel and the Java code for the Android implant. The operator argued the sale would fund development and let buyers audit the code.
Things frayed from there. A Spanish and Portuguese support channel went offline during a dispute with two former administrators. In July, the main channel said its admins would go independent and take their own customers with them. A Brazilian administrator reportedly bought the source and began running a separate fork. The advertised source price later fell to $10,000.
What are the copycats selling?
Cheap access, and a lot of it. A coordinated Telegram push offered BTMOB V4.1.2 and V4.2 lifetime access for $500, with claimed "RAT and server file source code" at $1,500. The same wording appeared across multiple channels pointing to handles like @thebtmobadmin and @btmobportal.
On April 26 the main channel pushed back, insisting it had only one official outlet and warning about impersonators. Whether that warning referred to the $500 sellers specifically is unclear.
| Version | Date | Headline offer |
|---|---|---|
| V2 | Jan 2025 | $700/month, $3,000 lifetime |
| Source code | May 2025 | $20,000 full package |
| V4 | Dec 2025 | Lifetime access, private servers |
| V4.5 | Apr 2026 | $1,200 lifetime, $7,000 server source |
Other sellers went lower still, offering weekly plans, free trials or custom branding. Some of those files are probably genuine forks. Others are almost certainly repackaged junk or outright scams aimed at other criminals.
Should ordinary phone users worry?
Yes, but not differently from the way you already should. BTMOB and its clones spread through fake apps, side-loaded installs or phishing links, not through the official Google Play store in most cases. Stick to Play, don't install Android apps from links sent by strangers, and be wary of any app that immediately asks for accessibility permissions. That single permission is what lets this kind of spyware read your screen and act on your behalf.
The real story here isn't the malware itself: it's that once source code leaks into this market, the original operator loses the ability to police the name. Every price cut signals desperation, not competition. Watch whether the official channel folds or pivots to a private-only model, because that's what cornered MaaS operators tend to do next.



