Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 3, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
SpyNote is a long-running Android remote access trojan (RAT) family, also widely known as SpyMax and sometimes associated with CypherRat-derived ecosystems.
Profile source: Mallory opens in a new tabSpyNote
SpyNote is a long-running Android remote access trojan (RAT) family, also widely known as SpyMax and sometimes associated with CypherRat-derived ecosystems. Active for several years, it became especially widespread after the leak of SpyNote v6.4 source code in 2020, which enabled extensive forking, commercialization, and reuse by criminal operators and some state-linked or espionage-oriented campaigns. SpyNote is commonly distributed as trojanized Android applications masquerading as legitimate software, including government-service apps, banking tools, messaging apps, VPNs, browsers, courier apps, and other themed lures. Delivery has been observed through phishing sites, direct download links, messaging platforms, social media, malicious ads, and other off-store channels, with some campaigns specifically using WhatsApp or Facebook-based social engineering.
On infected devices, SpyNote typically abuses Android Accessibility Services to escalate its effective control, automate interface interaction, inject gestures, enable keylogging, hinder removal, and facilitate broader surveillance without requiring root. It commonly seeks extensive permissions and may request device administrator privileges, activate persistence through broadcast receivers, and maintain long-lived command-and-control sessions over raw TCP sockets. Operators can use SpyNote to remotely control the device, capture keystrokes, intercept SMS including one-time passwords, harvest contacts and call logs, collect files and device information, track location, record audio, access the camera, capture screenshots or screen activity, and deploy phishing overlays for credential theft. Some variants also support dynamic code loading, runtime decryption, reflection-based evasion, emulator checks, and in-memory execution to resist analysis and detection.
SpyNote is supported by builder and panel ecosystems that allow operators to customize package names, component identifiers, permissions, lure branding, and command-and-control settings for each APK. Newer variants and related frameworks have incorporated obfuscation, droppers, embedded secondary payloads, native-library decryption, and anti-analysis features. Samples generated by the Flying Eagle Android malware framework have been detected as SpyNote-family malware, indicating code reuse or close lineage within the broader Android RAT ecosystem.
SpyNote has appeared in financially motivated fraud operations, surveillance campaigns, and targeted intrusions. Reported usage has included campaigns targeting Chinese users with fake public-service apps, Kurdish targets via Facebook-distributed Android backdoors, and high-value individuals in Southern Asia via WhatsApp-delivered payloads. Threat reporting has also linked SpyNote usage or derivatives to actors including OilRig, Kimsuky, APT-C-37, and other regional espionage operators, although attribution varies by campaign. The malware primarily targets Android devices and remains one of the more prominent mobile RAT families in the current threat landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
1d4da8cc24dcc9d8fcea103c3b705323014d1e908427766cf07df98365eddb06 57872c968de8211a957e02a148613455f70a7f13ef55596591c283f329fd33b9 a89676aa3bfb08a68ac0a668853e0f56512632e3034743d2771d476444c498e1 d08e92b1c40a589e06984695f8fecf7ff2e8466359058552051c9613c718b5ff dc5ee368e6ef268c678c4b6acbbf2dc7fe100d1e0c4bb92b79c80c52c9cc74c7 Reported operators
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.
This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.
MITRE ATT&CK
Reporting
Researchers at Hunt.io and NetAskari traced the Flying Eagle Android RAT from a leaked source archive to 170 active servers, expanding from two IP addresses cited in a Chinese state media notice through pivots on Let's Encrypt certificate subjects and an AdminPro panel fingerprint. The exposed infrastructure was concentrated across Hong Kong network providers including Antbox Networks Limited, Cognetcloud, CTG Server Limited, and Zillion Network Inc., indicating a broad and still-active hosting footprint for the malware platform. The investigation also examined the RAT's APK builder internals and uncovered evidence of a successor platform called Night Dragon that targets Chinese users. Researchers said a misspelled environment variable, SECRIT_KEY, in the leaked code led them to an open directory exposing a Windows XAMPP deployment of the same codebase, providing additional insight into the operators' development and administration environment.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.