Skip to content

SpyNote

SpyNote, also known as SpyMax, is an Android remote-access trojan and spyware family active since at least 2020.

Profile source: Mallory opens in a new tab

SpyNote

Family profile

SpyNote, also known as SpyMax, is an Android remote-access trojan and spyware family active since at least 2020. It abuses Android Accessibility Services to enable remote device interaction, automate interface actions, install or update applications, impede removal, keylog users, and capture authentication codes. SpyNote variants can collect and transmit SMS messages, call-related data, screen captures, audio or video recordings, location information, device details, and credentials harvested through impersonated banking, social-media, and other popular applications. SpyNote.C, also marketed as CypherRat, expanded the family’s financial-fraud functionality through banking-application impersonation, credential theft, and theft of multi-factor authentication codes. Its source-code leak in 2022 contributed to widespread derivative activity. Some variants have targeted cryptocurrency users by overlaying wallet applications and using Accessibility-driven automation to substitute attacker-controlled recipient addresses and initiate transfers. SpyNote is commonly delivered through phishing sites, deceptive applications, third-party distribution channels, and telephone-based social engineering. It has also been deployed through SecuriDropper to bypass Android 13 Restricted Settings protections. In contactless-payment fraud operations reported from Central Europe, attackers used SpyNote remote access to silently deploy WindRelay NFC-relay malware after persuading victims to install a personalized malicious application. SpyNote has also appeared in espionage activity attributed to Confucius and ITG18.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Aug 31, 2026
Feed role
C2
Host form
2 IP / 6 hostnames

Leading locations

  • DE2
  • GB2
  • NL2
  • RU1

Leading providers

  • Global Layer B.V.2
  • BrainStorm Network, Inc1
  • Kyonix Networks Limited1
  • OOO GETWIFI1
  • OVH SAS1
  • Yandex.Cloud LLC1

Infrastructure traits

  • Hosting 6

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
Confucius

经分析发现此类样本为开源安卓木马spynote改写而来。

Magic Hound

Spynote – Commercially available Android RAT (cracked versions available)

Syrian Electronic Army

A large portion of the malicious applications are SpyNote samples... Of the malicious applications in this campaign, 64 of 71 are SpyNote samples, a well known commercial surveillanceware family.

Preventive Security Service (PSS)

In addition to their custom-made malware, this group also utilized publicly available Android malware called SpyNote which had more functionality including remote device access and the ability to monitor calls.

Kimsuky

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

OilRig

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

APT-C-37

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

Pat-Bear

An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.

OilAlpha

This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.

BladeHawk

This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.

MITRE ATT&CK

SpyNote in ATT&CK

48 distinct techniques

Reporting

Research mentioning SpyNote

Jul 28
Huntio

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform. The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.

Jul 28
Reddit Netsec

Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs : r/netsec

Jan 1
Zscaler Threat Labz

Middle East users targeted by Molerats APT | Zscaler Blog

Multiple cyber-espionage operations targeted الفلسطينيين, activists, and organizations in the Palestinian territories with politically themed phishing lures and fake documents that delivered custom backdoors including Micropsia, Spark, Pierogi, and Scote. Reporting from Cisco Talos, Cybereason, and Palo Alto Networks links the activity to long-running Middle East-focused threat actors Arid Viper and MoleRATs (also known as the Gaza Cybergang), which repeatedly used Arabic-language decoys tied to regional politics, social-engineering archives hosted on services such as Dropbox and Egnyte, malicious RTF and Word files, and self-extracting executables to infect victims. The malware families provided persistent remote access and espionage capabilities including host reconnaissance, command execution, keylogging, screenshot capture, audio recording, file transfer, and HTTP-based command-and-control. Researchers said the operators also used evasion and targeting checks such as security-product discovery, Arabic language or keyboard validation, packers, and abuse of third-party platforms including Pastebin, Google+, and URL shorteners to hide infrastructure and retrieve C2 data. Across the campaigns, analysts observed largely consistent tradecraft over several years, indicating sustained intelligence collection against Palestinian political and civil-society targets despite repeated public exposure.

Jan 1
Cybereason

New Cyber Espionage Campaigns Targeting Palestinians - Part 2: The Discovery of the New, Mysterious Pierogi Backdoor

Jan 1
Cybereason

New Malware Arsenal Abusing Cloud Platforms in Middle East Espionage Campaign

Nov 17
Mitre Attack

Molerats, Operation Molerats, Gaza Cybergang, Group G0021 | MITRE ATT&CK®

Mar 22
Register Security

What does malware written in Go look like? A sample analyzed

Mar 21
Deepinstinct

Arid Gopher: Newest Micropsia Malware Variant | Deep Instinct

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.