
BTMob Uses WebSocket C2 for Real-Time Android Command Execution and Data Theft
BTMob is an Android remote access trojan (RAT) that uses WebSocket command-and-control (C2) communications to let attackers issue commands to infected devices in real time. The malware is linked to the broader CraxsRAT and SpySolr ecosystem and has evolved into a commercial fraud platform designed for banking theft, device surveillance, and large-scale malicious APK distribution. […]
The post BTMob Uses WebSocket C2 for Real-Time Android Command Execution and Data Theft appeared first on Cyber Security News.