BTMOB: A stealthy RAT burrowing deep into Android devices

2026-05-27T08:51:38Z40930a4ea8ce58e6f6558307e4a37b27e92fd0045db5cdf00838a03b1b28e379
APTRATandroidedr-killersgenAImalwaremobile-malwarenfc-paymentsphishingresearchscamssupply-chain

What happened

A May 2026 collection of ESET WeLiveSecurity research and news highlighting an uptick in advanced mobile and APT activity and the rising use of generative AI in malware. Notable items include BTMOB, a stealthy Android RAT; PromptSpy, the first observed Android malware abusing generative AI; a new NGate variant hidden in a trojanized NFC payment app; coverage of EDR-killer techniques; and multiple APT investigations (Webworm, FrostyNeighbor, GopherWhisper, ScarCruft, Sednit). The feed also covers supply‑chain attacks, large-scale fraudulent Android apps (CallPhantom), and consumer-targeted scam

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
40930a4ea8ce58e6f6558307e4a37b27e92fd0045db5cdf00838a03b1b28e379
Enrichment time
2026-05-27T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.