This software is the evolution of the earlier SpySolr spyware and poses a serious threat, as it allows attackers to fully control the infected device. Unlike simple malware, it is classified as a tool for conducting targeted cyberattacks and financial fraud, which has a modular architecture.
The main vector of the attack is the operation of Accessibility Services. This is the “heart” of the virus: having received permission to use this tool, BT MOB actually becomes an “invisible user” that stands between the operating system and the owner of the device. This allows malware to read the contents of any window, mimic the touches of the screen and intercept system events.
Remote Screen Sharing: Hackers can see and control the user screen in real time.
Accounting Theft: The virus uses the “overlay” technique (overheads of fake windows on top of these). When a user opens a banking application or social network, BT MOB replaces the login window with its own way to steal the login and password.
Device unlock : Using the special features API, the virus can mimic gestures to enter a graphical key or PIN code if it can spy on them earlier.
Keylogging: Recording all keystrokes on the keyboard, which allows you to intercept messages and passwords.
Files and Media: Browsing, deleting, renaming and stealing photos, videos and documents from phone memory.
Real-time espionage: The ability to covert audio recording via microphone and receive GPS location coordinates.
SMS and contact reading: The virus intercepts incoming messages (including two-factor authentication codes from banks) and steals a contact list.
Communication via WebSocket: Uses modern communication protocols with the command server (C2) to instantly execute the attacker commands.
There are no reviews for this product.