BTMob phishing apps hijack Android phones for fraud

Published August 18, 2026

BTMOB is a fraud toolkit that lets attackers build fake banking apps for Android phones. Once installed, it steals login details and lets criminals control the phone remotely to empty accounts.

Report priority
Medium
Targets
Android

How it works

  • Attackers send fake banking apps to Android users via phishing links.
  • When opened, the app steals login credentials and gives attackers full control over the phone to steal money.

What to do

Check if you've installed any unknown banking apps on your Android phone recently.

Uninstall any suspicious apps immediately and enable Google Play Protect to block future fake apps.

Technical details

An attacker sends you a phishing link pretending to be your bank's app. You download and install the fake app from a third-party site. The app steals your bank login and lets the attacker take over your phone to transfer money without your password.

BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise.