BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicious banking apps and exfiltrate sensitive data, capture screenshots, and remotely control devices. The relatively low cost of the license and adaptable phishing lures make it an attractive tool for both sophisticated and less experienced attackers.
The BTMOB RAT, initially identified by Cyble last year as a derivative of SpySolr, is being utilized in a campaign targeting users in Brazil and Latin America. This campaign leverages a MaaS model, offering a no-code interface for building malicious banking apps, significantly lowering the technical barrier to entry for cybercriminals. The RAT’s capabilities extend beyond typical banking Trojan functionality, including data exfiltration, screenshot capture, device control, and leveraging Android Accessibility Services for elevated permissions. The ESET security researchers highlighted the potential for significant damage, noting the RAT’s adaptability through a custom APK builder and phishing lures tailored to specific regions.
Distribution of the RAT occurs through Telegram channels and websites, coupled with phishing campaigns mimicking legitimate services like streaming platforms and cryptocurrency platforms. The malware is offered at a relatively low price of $5,000 for a lifetime license, reflecting the high returns in the mobile exploit market. This model, combined with the availability of free downloads from dark web forums, raises concerns about the potential for the malware to proliferate through resale or sharing within closed groups. The ability to adapt lures to specific regions provides attackers with a strong social-engineering advantage and broad geographic reach, as demonstrated by a campaign impersonating Argentina's tax and customs authorities.
To mitigate this threat, ESET recommends downloading apps only from the official Google Play Store, implementing basic phishing security hygiene, and exercising caution with unsolicited links and suspicious offers. The combination of these factors makes BTMOB a significant threat that extends beyond its initial target region.
