← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 18, 2026 · 15:10via Cyber Security News

BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers

Brief

BTMob is an Android banking malware platform built to turn phones into tools for fraud.

It reaches victims through fake apps, cloned download pages, and messages that look like routine customer support.

Once installed, it can give criminals a path to watch screens, steal information, and interfere with banking activity. The danger is not limited to one malicious app or one country.

BTMob is sold as a service, allowing different operators to build and distribute their own versions with local language lures, familiar brands, and payment-focused scams.

That model makes campaigns harder to track because the people running them may share code but use separate servers.

Analysts at QuimeraX identified a broad, live infrastructure behind the operation after examining leaked BTMob source packages and exposed servers.

Read more on Cyber Security News