BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

BTMob is an Android banking malware platform built to turn phones into tools for fraud.

It reaches victims through fake apps, cloned download pages, and messages that look like routine customer support.

Once installed, it can give criminals a path to watch screens, steal information, and interfere with banking activity.

BTMob is sold as a service, allowing different operators to build and distribute their own versions with local language lures, familiar brands, and payment-focused scams.

That model makes campaigns harder to track because the people running them may share code but use separate servers.

Analysts at QuimeraX identified a broad, live infrastructure behind the operation after examining leaked BTMob source packages and exposed servers.

Their findings show how a once more centralized Android remote-access tool developed into a franchised fraud platform that lowers the effort needed to launch device-takeover campaigns.

The reported activity includes highly tailored attacks in Brazil, where criminals used WhatsApp messages, stolen personal details, fake loyalty offers, and follow-up phone calls to persuade targets to sideload an Android package.

BTMOB distributed via a fake iNat TV site (Source – QuirmeraX)

The combination turns a familiar chat into a convincing route for financial theft, much like the tactics behind fake KYC banking scams.

QuimeraX said in a report shared with Cyber Security News (CSN) that for banks, mobile providers, and consumers, the impact is a widening pool of campaigns that can be adapted.

A fraudulent app may look different from one week to the next, while its underlying control system and device permissions remain capable of enabling account theft and unauthorised transfers.

BTMob Fraud-as-a-Service Platform

A Shodan search for BTMob’s distinctive fake error page found 1,402 hosts on port 3000.

Researchers verified several systems as full BTMob command-and-control servers, including one host that exposed web, database, remote desktop, and WebSocket services.

The platform packages the malicious Android app, a dropper, a desktop control panel, a server backend, and an automated APK builder.

An operator can enter an app name, icon, server address, and requested permissions, then receive a ready-to-share package.

This assembly-line setup resembles other paid Android spyware services that package infection tools for buyers rather than requiring them to write code.

BTMOB platform architecture (Source – QuirmeraX)

The source review also points to a reseller system that can create accounts and activation codes, helping the operation spread beyond its original developer.

BTMob is linked to the earlier CraxsRAT and SpySolr families, but its value to criminals lies in the business model: source code, branding options, and infrastructure can be reused by many independent groups.

The exposed setup helps defenders, but it does not reveal how many victims were infected or what data was stolen.

Victims are commonly led to install BTMob outside official app stores. QuimeraX documented pages masquerading as Google Play, package-tracking apps, streaming services, banking security tools, and government services.

Such pages display invented ratings and reviews to make the download look safe, a familiar pattern in fraudulent Play Store downloads.

In one observed Brazilian case, attackers began with a WhatsApp profile using a retailer’s branding and accurate victim data.

The fake loyalty offer with a binary accept (Source – QuirmeraX)

A fake virtual assistant offered a loyalty upgrade, then a caller spent several minutes guiding the target through enabling installations from unknown sources.

The malicious APK arrived in WhatsApp shortly after the call, echoing the risk from fraudulent support call campaigns.

Users should treat unsolicited requests to install an APK, enable Accessibility services, or change unknown-app settings as warning signs.

Download financial, government, and delivery apps only through verified stores or official websites, and independently contact an organisation using a trusted number if a message or caller claims urgent action is needed.

Security teams can hunt for the stable BTMob server patterns and block identified infrastructure, while monitoring unusual WebSocket traffic and sideloaded applications.

Indicators of Compromise (IoCs):-

Type Indicator Description
APK file name lnat-tv-pro.apk BTMob v2.5 sample distributed through a phishing site impersonating iNat TV
Executable file BTMob.exe VB.NET BTMob operator desktop panel
Executable file SolrStarter.exe APK-builder component
Executable file SolrWorker.exe APK-builder component
Shodan query http.html_hash:-983012381 port:3000 Query used to locate hosts serving the BTMob fake 403 page
Shodan query html:"painel de controle elite" Query used to locate associated bypass-panel instances
HTML hash -983012381 Fake 403 page fingerprint observed on port 3000
C2 port signature 80, 3000, 3306, 8080, 3389 IIS, Node.js/Express, MySQL, WebSocket, and RDP services associated with confirmed BTMob infrastructure
Network pattern HTTP POST to /yaarsa/private/yarsap_*.php BTMob C2 communication pattern for IDS and proxy monitoring
WebSocket pattern idf, sidf, cip, itype:"Slr_client" JSON fields associated with BTMob WebSocket traffic
WebSocket URL pattern ws://<host>:8080/con BTMob WebSocket command-and-control connection
HTTP response 426 Upgrade Required Expected response from the BTMob WebSocket service on port 8080 when reached through regular HTTP
Domain server[.]yaarsa[.]com Earlier BTMob command-and-control server
Domain btmobrat[.]net BTMob storefront
Domain playstoreapps[.]pro RADAR Android processing and bypass platform
Domain playstoreap[.]lovable[.]app Fake Google Play Store distribution site
Domain rastrear-encomendas2[.]pages[.]dev Fake Rodonaves package-tracking distribution page
Domain meusdownloads[.]site Fake Play Store distribution page
IP address 77[.]111[.]101[.]24 Confirmed BTMob command-and-control server
C2 backend path /yaarsa/private/yarsap_85401.php Master configuration file containing database credentials, crypto keys, and User-Agent data
C2 backend path /yaarsa/private/createacc.php Reseller-authenticated account-creation API
C2 backend path /yaarsa/user/loginbt.php BTMob operator login panel
C2 backend path /yaarsa/user/loginbt3.php BTMob operator login panel with Google Authenticator 2FA
C2 backend path /yaarsa/user/login.php Decoy fake-403 redirect page
C2 backend path /yaarsa/index.php Decoy fake-403 redirect page
C2 backend file /yaarsa/server/websocket-server.js Node.js and WebSocket server component

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world