New BTMOB Android Malware Enables Full Device Takeover

2026-05-28T13:24:10Zbc9d2ba26fd2c9d853303ef3b99e4d6a51b1329b0cf15e44a142e8f704b10e27
account takeoverai threat defenseai-powered attacksandroid malwarebtmobcontainer image exposuredata exfiltrationedamameforticlient emsfortinetgiteamobile takeoveropen source supply chainpatch nowphishingpretalxproject lightwellremote access trojanzero-day

What happened

SecurityWeek feed highlights several high-impact incidents and industry responses: (1) A new Android malware family called BTMOB delivered via phishing can achieve full device takeover, combining financial theft, data exfiltration and remote access — review mobile phishing controls and monitor endpoints. (2) A critical FortiClient EMS vulnerability was patched in April after being exploited as a zero-day; immediate patching/hotfix deployment and investigation of suspected intrusions is advised. (3) A Gitea vulnerability exposed ~30,000 deployments allowing attackers to pull private container/­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
bc9d2ba26fd2c9d853303ef3b99e4d6a51b1329b0cf15e44a142e8f704b10e27
Enrichment time
2026-05-28T13:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New BTMOB Android Malware Enables Full Device Takeover · Baitaphish