BTMob Uses WebSocket C2 for Real-Time Android Command Execution and Data Theft
Brief
BTMob is an Android remote access trojan (RAT) that uses WebSocket command-and-control (C2) communications to let attackers issue commands to infected devices in real time.
The malware is linked to the broader CraxsRAT and SpySolr ecosystem and has evolved into a commercial fraud platform designed for banking theft, device surveillance, and large-scale malicious APK distribution.
Researchers first publicly documented BTMob in February 2025 after discovering an APK named lnat-tv-pro.apk , distributed through a phishing website impersonating the Turkish iNat TV streaming service.
Later leaked source-code packages for versions 4.
- 7 and 4. 6 revealed a complete crimeware toolkit, including an Android payload, dropper, Windows operator panel, PHP/MySQL backend, WebSocket server, and automated APK builder.
