Skip to content

SpyNote

SpyNote is a long-running Android remote access trojan (RAT) family, also widely known as SpyMax and sometimes associated with CypherRat-derived ecosystems.

Profile source: Mallory opens in a new tab

SpyNote

Family profile

SpyNote is a long-running Android remote access trojan (RAT) family, also widely known as SpyMax and sometimes associated with CypherRat-derived ecosystems. Active for several years, it became especially widespread after the leak of SpyNote v6.4 source code in 2020, which enabled extensive forking, commercialization, and reuse by criminal operators and some state-linked or espionage-oriented campaigns. SpyNote is commonly distributed as trojanized Android applications masquerading as legitimate software, including government-service apps, banking tools, messaging apps, VPNs, browsers, courier apps, and other themed lures. Delivery has been observed through phishing sites, direct download links, messaging platforms, social media, malicious ads, and other off-store channels, with some campaigns specifically using WhatsApp or Facebook-based social engineering.

On infected devices, SpyNote typically abuses Android Accessibility Services to escalate its effective control, automate interface interaction, inject gestures, enable keylogging, hinder removal, and facilitate broader surveillance without requiring root. It commonly seeks extensive permissions and may request device administrator privileges, activate persistence through broadcast receivers, and maintain long-lived command-and-control sessions over raw TCP sockets. Operators can use SpyNote to remotely control the device, capture keystrokes, intercept SMS including one-time passwords, harvest contacts and call logs, collect files and device information, track location, record audio, access the camera, capture screenshots or screen activity, and deploy phishing overlays for credential theft. Some variants also support dynamic code loading, runtime decryption, reflection-based evasion, emulator checks, and in-memory execution to resist analysis and detection.

SpyNote is supported by builder and panel ecosystems that allow operators to customize package names, component identifiers, permissions, lure branding, and command-and-control settings for each APK. Newer variants and related frameworks have incorporated obfuscation, droppers, embedded secondary payloads, native-library decryption, and anti-analysis features. Samples generated by the Flying Eagle Android malware framework have been detected as SpyNote-family malware, indicating code reuse or close lineage within the broader Android RAT ecosystem.

SpyNote has appeared in financially motivated fraud operations, surveillance campaigns, and targeted intrusions. Reported usage has included campaigns targeting Chinese users with fake public-service apps, Kurdish targets via Facebook-distributed Android backdoors, and high-value individuals in Southern Asia via WhatsApp-delivered payloads. Threat reporting has also linked SpyNote usage or derivatives to actors including OilRig, Kimsuky, APT-C-37, and other regional espionage operators, although attribution varies by campaign. The malware primarily targets Android devices and remains one of the more prominent mobile RAT families in the current threat landscape.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 3, 2026
Last activity
Aug 3, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • RU1

Leading providers

  • Yandex.Cloud LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
Kimsuky

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

OilRig

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

APT-C-37

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

Pat-Bear

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

OilAlpha

This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.

BladeHawk

This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.

MITRE ATT&CK

SpyNote in ATT&CK

26 distinct techniques

Reporting

Research mentioning SpyNote

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.