BTMOB: A stealthy RAT burrowing deep into Android devices
2026-05-27T08:51:38Z•40930a4ea8ce58e6f6558307e4a37b27e92fd0045db5cdf00838a03b1b28e379
APTRATandroidedr-killersgenAImalwaremobile-malwarenfc-paymentsphishingresearchscamssupply-chain
What happened
A May 2026 collection of ESET WeLiveSecurity research and news highlighting an uptick in advanced mobile and APT activity and the rising use of generative AI in malware. Notable items include BTMOB, a stealthy Android RAT; PromptSpy, the first observed Android malware abusing generative AI; a new NGate variant hidden in a trojanized NFC payment app; coverage of EDR-killer techniques; and multiple APT investigations (Webworm, FrostyNeighbor, GopherWhisper, ScarCruft, Sednit). The feed also covers supply‑chain attacks, large-scale fraudulent Android apps (CallPhantom), and consumer-targeted scam
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 40930a4ea8ce58e6f6558307e4a37b27e92fd0045db5cdf00838a03b1b28e379
- Enrichment time
- 2026-05-27T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.