"More than 4,000 mobile devices were connected," a January 2025 announcement claimed, as its operator wrestled with server errors and heavy traffic they could not immediately explain, according to Flare researchers.
From a single service to a fragmented BTMOB market
BTMOB began as a classic malware-as-a-service (MaaS): an Android remote access trojan sold with droppers, a payload builder, a Windows operator panel, server infrastructure, and phishing tools. Flare’s review of thousands of underground posts shows that what started as an apparently centrally operated service splintered. The BTMOB name now represents a patchwork of offerings — official releases, private servers run by independent administrators, alleged source-code buyers, reseller panels, and accounts that imply an official connection but whose authenticity cannot be verified.
Source-code sales and infrastructure offers shifted control
In May 2025 the main channel offered complete BTMOB source code and setup tutorials for $20,000, including PHP and Node.js server components, a VB.NET control panel, and Java Android code. The operator framed this as a revenue and transparency move, saying sales would let customers inspect the code and produce custom versions without ending the original service’s development. The advertised price later dropped to $10,000. By December, BTMOB V4 had reemphasized lifetime access, private servers, custom versions and recurring fees. When V4.5 arrived in April 2026, the official public offer listed a $1,200 lifetime account, a $3,000 private server with multiple accounts, and server source code for $7,000 — suggesting that infrastructure-level code sales remained part of the official business even as sales became narrower and cheaper than the full-code package promoted in 2025.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Coordinated Telegram reseller campaigns and impersonators
Parallel to official offers, Flare documented coordinated reseller advertising on Telegram. Representative posts promoted BTMOB V4.1.2 and V4.2 access with a lifetime price of $500 and "RAT and server file source code" at $1,500, directing buyers to contact @thebtmobadmin and @btmobportal. Nearly identical messages appeared across multiple groups and accounts; later variants promoted purported V4.5.4 access at similar prices with different contact handles. Other actors offered even lower-cost plans, free trials, and reseller panels that invited buyers to become BTMOB sellers.
Flare cautions — and the records bear this out — that these advertisements do not prove authenticity. They may represent genuine reselling, modified versions, repackaged software, nonfunctional files, or outright scams. On April 26 the main BTMOB channel publicly denied responsibility for other accounts and stated it had only one official channel.
Official development persisted into 2026
Despite fragmentation, the main channel continued to publish updates. BTMOB V4.1 was released in February 2026 and V4.5 in April. V4.5 introduced multiple server locations and a central page for managing multiple servers, indicating ongoing development focused on infrastructure flexibility and multi-server management. The operator also acknowledged operational problems earlier in the life cycle — in January 2025 it reported errors while claiming those thousands of connected devices — underscoring how infrastructure strain and administrative disputes factored into the service’s evolution.
What this means for technologists, policymakers, and procurement leaders
- Technologists and security teams: the BTMOB case shows how a single malware product can spawn diverse variants and distribution channels. Defenders should watch for multiple panels, altered binaries, and resold source code that may circumvent prior detection strategies or introduce new behavior.
- Policymakers and regulators: the advertised sales of source code and server infrastructure — including public price points ($20,000, $10,000, $7,000) and recurring offers — highlight a criminal market with monetized tiers. That commercialization can accelerate proliferation and complicate attribution or takedown efforts.
- Procurement leaders at affected enterprises: lower-priced reseller offers and impersonating accounts mean adversaries may obtain different quality levels of the same-named tool. Evaluating a threat requires not only technical signatures but also assessment of seller provenance, support channels, and evidence that claimed services function as advertised.
BTMOB’s trajectory — central control giving way to source-code transfers, administrative splits, and coordinated reselling campaigns — illustrates a wider dynamic in underground software markets: the moment an operator monetizes the recipe, dozens of variants can follow. Whether the resulting copies improve, degrade, or simply confuse detection, the name "BTMOB" no longer identifies a single operator, infrastructure or level of service — it identifies a marketplace with competing sellers and uncertain provenance.
https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/




