The Android RAT’s official operation is surrounded by cheaper resellers, alleged source-code vendors, independent server owners, and possible impersonators.

BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.

Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.

Posts reviewed by Flare show the channel presenting itself as BTMOB’s official outlet continuing to release new versions and sell access, private infrastructure, and source code. Around it, other actors advertise cheaper subscriptions, reseller panels, purported source files, and versions carrying the BTMOB name.

To understand how this ecosystem developed, the research examined thousands of posts from forums and chat platforms, following BTMOB’s underground activity from its early stages in 2025 through the present.