← Back to feed
PhishingEmerging1 sourceAug 18, 2026 · 10:30via CyberPress

BTMob Uses WebSocket C2 for Real-Time Android Command Execution and Data Theft

Brief

BTMob is an Android remote access trojan (RAT) that uses WebSocket command-and-control (C2) communications to let attackers issue commands to infected devices in real time.

The malware is linked to the broader CraxsRAT and SpySolr ecosystem and has evolved into a commercial fraud platform designed for banking theft, device surveillance, and large-scale malicious APK distribution.

Researchers first publicly documented BTMob in February 2025 after discovering an APK named lnat-tv-pro.apk , distributed through a phishing website impersonating the Turkish iNat TV streaming service.

Later leaked source-code packages for versions 4.

  • 7 and 4. 6 revealed a complete crimeware toolkit, including an Android payload, dropper, Windows operator panel, PHP/MySQL backend, WebSocket server, and automated APK builder.
Read more on CyberPress