There is, sad to say, no shortage of Android malware out there. An estimated user base of almost 4 billion equals one heck of a lot of payload potential, after all. And now a no-code Android remote access trojan (RAT) is threatening colossal damage.
It’s called BTMOB, but that doesnโt appear to stand for anything other than absolute chaos. This Android RAT ,is notable, ESET researchers say, โfor the damage it can wreakโ.
The main reason for this is that attackers don’t need any code-writing skills. Using the Android Package Kit builder provided with BTMOB, attackers can enable new payload generation and phishing lure customisation without writing extra code.
As such, โdefenders should expect rapid payload turnover rather than a stable set of threats,โ Daniel Cunha Barbosa, a security researcher at ESET has warned.
While BTMOB is hardly new, having first appeared on the threat intelligence radar a year ago, the May 26 ESET deep-dive analysis surfaced new attacks and new causes for concern. The biggest being that this thing really does lower the barriers for device compromise.
Who the Android banking trojan BTMOB is attacking
First things first. The latest attacks are targeting users in South/Latin America, but that doesnโt mean it will stay there.
โThe combination of phishing-led delivery, ready-made app-building tooling and device takeover capabilities,โ Barbosa said, makes BTMOB a threat across geographical boundaries.
This is no ordinary banking trojan. It isn’t focused solely on your financial credentials or transactions, but rather a whole armoury of payload options. These include:
- sensitive data exfiltration
- activity recording
- screenshot capture
- and total device takeover.
This isn’t surprising, as it gives away the malware ancestry, with BTMOB evolving from an Android spyware threat known as SpySolr that harvested call logs, device audio, SMS messages etc.
Why cybercriminals love BTMOB… and how you can fight it
From the cybercriminal perspective, BTMOB is targeted directly at the malware-as-a-service sector. Given the functionality it provides for even the least technically adept user, the ยฃ4,000 lifetime licence means that the barrier for entry is low to a hugely profitable criminal enterprise. Even with an additional monthly support fee added to the bill.
Then thereโs what ESET refers to as a familiar risk with commercial malware: โaccess rarely stays contained forever, and the tool can move into secondary markets through resale, barter or sharing inside closed groupsโ. Ignore this one at your peril, in other words.ย
The good news, if you can call it that, is that the BTMOB attack chain starts with phishing campaigns to push targets to fake app stores where users are prompted to install a malicious APK.
Which means that the primary mitigation is a simple one on paper, apparently much harder in practice: organisations must mandate users to only download software from official repositories.
โCorporate security teams must make it clear to employees that a single rogue download could expose the companyโs crown jewels,โ Barbosa sagely concluded.