Mark RadarMARK RADAR
EN
Event File FINTECH Financial Cybersecurity

Android Trojan BTMOB Targets Financial Services Users to Steal Credentials

1 reports · First detected 2026-06-02 · Last active 2026-06-02

BTMOB is a remote-access Trojan targeting Android devices, primarily those of financial services users in Latin America. Cybersecurity company ESET said the malware is sold under a malware-as-a-service model, lowering the barrier to launching attacks. Once a device is compromised, bank accounts, login credentials and funds may all be at risk.

As of July 20, 2026, ESET warned that BTMOB was spreading through phishing websites impersonating cryptocurrency platforms or streaming services and tricking users into installing the malware. The Trojan can steal account information and credentials and remotely control victims’ devices. No figures have been disclosed for the number of victims or the amount of money involved, and the date when the malware was first detected remains unknown.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)