Android Trojan BTMOB Targets Financial Services Users to Steal Credentials
BTMOB is a remote-access Trojan targeting Android devices, primarily those of financial services users in Latin America. Cybersecurity company ESET said the malware is sold under a malware-as-a-service model, lowering the barrier to launching attacks. Once a device is compromised, bank accounts, login credentials and funds may all be at risk.
As of July 20, 2026, ESET warned that BTMOB was spreading through phishing websites impersonating cryptocurrency platforms or streaming services and tricking users into installing the malware. The Trojan can steal account information and credentials and remotely control victims’ devices. No figures have been disclosed for the number of victims or the amount of money involved, and the date when the malware was first detected remains unknown.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.