BTMOB has spread beyond a single Android malware service into a market of official releases, private servers, source-code buyers, resellers, and offers of uncertain authenticity. That finding comes from a BleepingComputer page labeled “Sponsored and written by Flare”; the article treats it as Flare’s sponsored research rather than independent BleepingComputer reporting. Flare reviewed thousands of posts across underground forums and chat platforms from early 2025 through 2026.
The change matters to mobile-security teams because the BTMOB name no longer implies one operator, one backend, or one stable build. Flare says the apparent official operation remains active, but cheaper third parties advertise their own subscriptions, panels, server files, and purported source code. Some may be genuine derivatives; others may be repackaged files, broken copies, or scams. Flare could not authenticate many of those offers.
Source sales turned one service into several
BTMOB packages an Android remote-access trojan with droppers, a payload builder, a Windows operator panel, server infrastructure, and phishing tools. Its builder lets a customer configure a malicious application without developing one from scratch.
Flare traced the business shift through the apparent official channel. In January 2025, the operator advertised BTMOB V2 for $700 a month, $3,000 for lifetime access, or $5,000 plus recurring payments for private infrastructure and support. The following month, the channel acknowledged server problems and claimed more than 4,000 devices were connected. Flare could not verify that device count or the operator’s explanation for the outage.
In May 2025, the same channel offered complete source code and setup tutorials for $20,000, describing PHP and Node.js server components, a VB.NET panel, and Java Android code. The advertised price later fell to $10,000. A support channel then reported a dispute with two former administrators, and the main channel said in July that administrators would operate independently. It also said a Brazilian administrator had bought the source and maintained a separate version.
That sequence provides a plausible mechanism for fragmentation: code and infrastructure moved outside the original operator’s control, while independent administrators acquired their own customers and reputations. It does not prove that every later seller obtained authentic source.
The BTMOB label now carries weak attribution
By 2026, Flare observed coordinated Telegram advertisements offering alleged V4.1.2 and V4.2 lifetime access for $500 and purported RAT and server source code for $1,500. Other advertisements sold weekly access, reseller panels, custom branding, or claimed free downloads. The apparent official channel, meanwhile, warned in April that it had only one official outlet and disclaimed other accounts using the project name.
Official development also continued. The main channel released V4.1 in February and V4.5 in April, advertising a $1,200 lifetime account, a $3,000 private server with multiple accounts, or server source code for $7,000. According to Flare, V4.5 added several server locations and a central page for managing them.
Those observations support a market map, not a precise family tree. Reused branding does not establish common ownership, shared infrastructure, or identical code. Likewise, similar panels or pricing do not prove that a seller controls working malware.

Figure details
The apparent official BTMOB service first sold access, then advertised source and server code. Administrators later operated independently, while resellers and offers of uncertain authenticity reused the name. The result is a market map rather than a verified family tree, so defenders should correlate APK installation, high-risk permissions, persistence, capture, and command-and-control behavior.
Active delivery confirms the device risk
The sales-market evidence is partly observational, but BTMOB’s use in an attack chain is independently documented. Kaspersky reported an active campaign in which a fake Starlink application delivered BeatBanker, which then installed BTMOB. The phishing pages mimicked Google Play and induced users to grant installation permissions.
Kaspersky says the installed RAT can obtain permissions, suppress system notifications, capture screen-lock credentials, access both cameras, track GPS location, and collect sensitive data. The companion Securelist analysis describes the BeatBanker component’s foreground service and silent media playback used to resist process removal. Kaspersky detects the chain as HEUR:Trojan-Dropper.AndroidOS.BeatBanker and HEUR:Trojan-Dropper.AndroidOS.Banker.*; those names describe that observed delivery chain, not every product sold as BTMOB.
Close on device behavior, not a brand name
Mobile defenders should treat BTMOB as a behavior cluster with multiple possible distributors. In managed Android fleets, first inventory devices that permit installation from unknown sources, then review newly granted Accessibility Service, device-administration, notification-listener, screen-capture, camera, microphone, and location permissions. Correlate those changes with APK installation telemetry, fake-store browser history, persistent foreground notifications, unusual media playback, and mobile-security detections.
Contain a suspected device before using it to reset credentials: remove it from trusted authentication paths, revoke active sessions, rotate credentials from a known-clean system, and preserve the APK, package name, signing certificate, hashes, network destinations, and permission history. A reseller’s label is useful context, but it is not an incident-closing indicator.
Close only when every managed device either blocks unapproved sideloading or has a documented exception; suspicious high-risk permission grants are explained; delivered APKs and their signers are accounted for; affected sessions and credentials are revoked; and no unexplained remote-control, capture, persistence, or command-and-control activity remains.
