Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Aug 31, 2026
- Feed role
- C2
- Host form
- 2 IP / 6 hostnames
SpyNote, also known as SpyMax, is an Android remote-access trojan and spyware family active since at least 2020.
Profile source: Mallory opens in a new tabSpyNote
SpyNote, also known as SpyMax, is an Android remote-access trojan and spyware family active since at least 2020. It abuses Android Accessibility Services to enable remote device interaction, automate interface actions, install or update applications, impede removal, keylog users, and capture authentication codes. SpyNote variants can collect and transmit SMS messages, call-related data, screen captures, audio or video recordings, location information, device details, and credentials harvested through impersonated banking, social-media, and other popular applications. SpyNote.C, also marketed as CypherRat, expanded the family’s financial-fraud functionality through banking-application impersonation, credential theft, and theft of multi-factor authentication codes. Its source-code leak in 2022 contributed to widespread derivative activity. Some variants have targeted cryptocurrency users by overlaying wallet applications and using Accessibility-driven automation to substitute attacker-controlled recipient addresses and initiate transfers. SpyNote is commonly delivered through phishing sites, deceptive applications, third-party distribution channels, and telephone-based social engineering. It has also been deployed through SecuriDropper to bypass Android 13 Restricted Settings protections. In contactless-payment fraud operations reported from Central Europe, attackers used SpyNote remote access to silently deploy WindRelay NFC-relay malware after persuading victims to install a personalized malicious application. SpyNote has also appeared in espionage activity attributed to Confucius and ITG18.
C2 tracking
Derp observations, rolling seven-day window
Samples
45a576381409b82fb40689b7ddfa0b7ab3fe774e81d4a2da9a98435a2f2207a5 730afe6605cfb0e3791276199c49d2af11585c5d470ee6f4c318040faf53f1a7 8bd3e2cd97213ce359eb214db16468c591e25094f6737d9e90040d5ec2eee25f ca53f94f4a75bc5d42df92e04442efc6a7a8503d2b3b517b8b0e6efeff570b92 eae946eeccf3a0a4a2cac02ccdb5f45ab6cfd6db3d31c67c454843938192af9c 2ff30562865d1de965db007a34e2f12a90ef548dd1188ab0f1ac42fb0769eafe 6dcc528cc2e2e18fab511442550f9fa6ebecdc4c82d5a8cb3aec149d10d82393 9f6526fbe31945e3dc9d199379625007286a647343e3d1781accae3f0240d0e9 e20fecdbd1efe8f3a8aa9693267a9fdab65500f1616f04428bb62c5425d401e0 f704197693162b90e721037732a740986a443b4d6c28ac8c7a869318e8b8b6ed Reported operators
经分析发现此类样本为开源安卓木马spynote改写而来。
Spynote – Commercially available Android RAT (cracked versions available)
A large portion of the malicious applications are SpyNote samples... Of the malicious applications in this campaign, 64 of 71 are SpyNote samples, a well known commercial surveillanceware family.
In addition to their custom-made malware, this group also utilized publicly available Android malware called SpyNote which had more functionality including remote device access and the ability to monitor calls.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.
This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.
MITRE ATT&CK
Reporting
Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform. The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.
Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.