The Android RAT’s official operation is surrounded by cheaper resellers, alleged source-code vendors, independent server owners, and possible impersonators.

BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.

Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.

Posts reviewed by Flare show the channel presenting itself as BTMOB’s official outlet continuing to release new versions and sell access, private infrastructure, and source code. Around it, other actors advertise cheaper subscriptions, reseller panels, purported source files, and versions carrying the BTMOB name.

To understand how this ecosystem developed, the research examined thousands of posts from forums and chat platforms, following BTMOB’s underground activity from its early stages in 2025 through the present.

The material includes announcements from the apparent official operation, alongside activity by resellers, source-code vendors, and other actors using the BTMOB name.

Key points

  • BTMOB developed from a centrally operated malware service into a broader ecosystem involving private servers, source-code buyers, custom versions, and independent administrators.

  • The official operator repeatedly reduced the price, while third parties advertised alleged access and source files at substantially lower prices.

  • The BTMOB name is now used by coordinated reseller campaigns and accounts that imply an official connection, although the authenticity of many offers cannot be verified.

  • The official BTMOB operation remained active as a secondary market developed around it, continuing to release new versions and advertise access, private infrastructure, and server code.
    

What is BTMOB?

BTMOB is primarily an Android remote access trojan where its malicious application is installed on a victim’s phone to steal information and provide remote control. It is sold as a malware-as-a-service package that includes droppers, a payload builder, a Windows-based operator panel, server infrastructure, and tools for phishing and credential-stealing.

BTMOB attracts actors because it provides both the malware and much of what is needed to operate it. Customers can use a software tool to configure and create malicious Android applications without developing them from scratch.

Depending on the package purchased, they may also receive access to server infrastructure, customized versions, and technical support.

BTMOB shows how quickly a single MaaS operation can splinter into resellers, source-code buyers, and impersonators across Telegram.

Flare tracks these criminal marketplaces and channels as they evolve, so your team can spot new RAT variants, panels, and sellers before they reach your organization.

Track Emerging Threats for Free with Flare## Infrastructure problems became a sales opportunity

In January 2025, the official channel advertised BTMOB V2 for $700 a month, $3,000 for a lifetime license, or $5,000 plus monthly payments for private infrastructure and support.

Less than a month later, it acknowledged server errors. The operator claimed that more than 4,000 mobile devices were connected but could not determine whether heavy traffic represented customer activity or a DDoS attack. See screenshots below:

Although these claims could not be verified, the announcement provides insight into how BTMOB operated at the early stages, with the apparent official operator managing its shared infrastructure and customer communications.

Selling the code behind the service

In May 2025, the channel offered complete BTMOB source code and setup tutorials for $20,000. The package included its PHP and Node.js server components, VB.NET control panel, and Java Android code. See screenshot below:

The operator later explained that source sales would generate profit, let customers inspect the code, and enable custom or alternative versions without ending the development of the original service.

At the same time, the organization showed signs of fragmentation. A Spanish- and Portuguese-language support channel announced that servers were temporarily offline during a dispute with two former administrators. It suspended sales and accused them of acting in bad faith.

In July, the main channel said its administrators would begin operating independently, becoming responsible for their own clients and reputations. It also said a Brazilian administrator had purchased the source and was maintaining a separate version.

The advertised source-code price subsequently fell to $10,000. When BTMOB V4 arrived in December, the public offer emphasized lifetime access, private servers, custom versions, and recurring fees.

Customers were also told that migration from V3 required contacting the operator.

A cheaper secondary market

During the same period, a coordinated Telegram campaign offered BTMOB V4.1.2 and V4.2 access. One representative advertisement priced lifetime access at $500 and “RAT and server file source code” at $1,500, directing buyers to @thebtmobadmin and @btmobportal.

The advertisement was repeatedly distributed across multiple Telegram groups by several accounts using substantially the same wording, prices, and contacts. A later variation promoted purported V4.5.4 access at similar prices but used another contact handle.

The timing is notable, although it does not prove that the official warning referred to these particular sellers. On April 26, the main BTMOB channel said it had only one official channel and denied responsibility for other accounts claiming to represent the project. See screenshot below:

Other actors advertised even lower prices of the different options. One offered several BTMOB versions through weekly, monthly, and lifetime plans, including purported source code. Another invited customers to become BTMOB sellers by purchasing inexpensive user or administrator panels.

Substantially similar source-code and reseller-panel advertisements appeared across numerous sites, frequently pointing to the same contact and website. Separate posts offered free trials and an $800 lifetime license, custom branding, and alleged free source downloads.

None of these advertisements proves that the files are authentic. Some may represent genuine reselling or modified versions while others may involve repackaged software, nonfunctional files, or scams.

Official development continued in 2026

The main channel released BTMOB V4.1 in February 2026 and V4.5 in April. The V4.5 offered a $1,200 lifetime account, a $3,000 private server with multiple accounts, or server source code for $7,000.

This may indicate that infrastructure-level code sales remained part of the official business, although the offer had become narrower and cheaper than the complete package promoted in 2025.

V4.5 also introduced several server locations and a central page for managing multiple servers.

From a single service to a fragmented market

When the creator of a successful product sells its recipe, others can reproduce it without bearing the original development costs. Cheaper versions emerge, but their quality varies: some may improve on the original, while others are unstable, poorly supported or even fraudulent.

This appears to be what happened with BTMOB. We do not know what prompted the source-code sale or the dispute between its administrators.

However, what began as an established MaaS operation seems to have developed into a mixture of independently managed versions, cheaper copies, competing sales channels and offers of uncertain legitimacy.

As a result, the BTMOB name no longer identifies a single operator, infrastructure or level of service.

In this fragmented market, buyers must evaluate not only the software but also the seller’s reputation, technical support and evidence that the service actually works.

Sponsored and written by Flare.