Back to Feed
MalwareApr 19, 2026

‼️BTMOB v4.1, an Android banking trojan and remote access tool (RAT), is being sold as full sourc...

BTMOB v4.1 Android banking trojan and RAT source code sold on cybercrime forum.

Summary

BTMOB v4.1, an Android banking trojan and remote access tool (RAT), is being publicly sold as full source code on a cybercrime forum by threat actor isExploit. The seller is marketing it as 'the best RAT of 2026,' indicating active development and high confidence in the malware's capabilities. This source code availability significantly increases the risk of variants and derivative attacks targeting Android banking users.

Indicators of Compromise

  • malware — BTMOB

Entities

isExploit (threat_actor)Android (technology)