Tag: BTMOB Android malware

BTMOB Android malware service generates custom phishing payloads
News

BTMOB Android malware service generates custom phishing payloads

Cybercriminals can create malware payloads customized to phishing lures using the builder interface of an Android remote access trojan called BTMOB. The malware has many characteristics, such as the ability to take screenshots, intercept bank transactions, steal specific data, and operate remotely. According to cybersecurity firm ESET, BTMOB functions as a malware-as-a-service (MaaS) platform and is publicly promoted on the clearweb. The offer's APK builder makes it simple to modify the payload without requiring any coding knowledge. Customers can specify what the app should do (e.g., disable Google Play, conceal its icon to make it more difficult to remove from the device, or block sleep mode) and choose from a set of permissions the APK requests upon installation. It should ...