SpyNote is a long-running Android remote access trojan (RAT) and spyware family also known as SpyMax and CypherRat. It has been active for years in the mobile threat landscape and expanded significantly after the leak of SpyNote v6.4 source code in 2020, which enabled widespread forks, derivative builders, and commercialization in malware-as-a-service style offerings. Related variants and derivatives have been associated with names such as Craxs RAT.
SpyNote is primarily distributed as trojanized Android applications masquerading as legitimate software, including messaging, banking, browser, VPN, courier, utility, and event-themed apps. Delivery commonly relies on social engineering rather than exploit-based compromise, with campaigns using phishing pages, direct download links, malicious ads, SMS messages, email links, messaging platforms, and social-media posts. Operators often instruct victims to sideload apps, disable Play Protect, or grant installation from unknown sources. Some campaigns have used loader apps, QR-code redirection, and fake app-store style landing pages.
Once installed, SpyNote requests broad Android permissions and commonly abuses Accessibility Services to escalate control over the device without root. It can obtain device administrator privileges, resist removal, survive reboots through broadcast receivers, and maintain long-lived command-and-control sessions over persistent TCP communications. Newer variants employ obfuscation, reflection, dynamic code loading, embedded secondary payloads, native-library decryption, runtime-only decoding, and in-memory execution to hinder analysis and evade detection.
SpyNote provides extensive surveillance and remote-control functionality. Documented capabilities include collection of device information, contacts, SMS messages, call logs, files, account data, and location; microphone and camera access for audio and video capture; screen monitoring and screenshots; accessibility-based keylogging and UI automation; overlay-based credential phishing; SMS interception including one-time passcodes; command execution; and remote interaction with the device interface. Some variants also support premium-rate SMS abuse and can act as droppers for additional malicious functionality.
SpyNote has appeared in both cybercriminal and espionage-linked operations. Reporting has linked its use in various campaigns to actors including OilRig, Kimsuky, APT43, APT-C-37, BladeHawk, and activity aligned with Iranian and other regional targeting. Observed targeting has included government entities, NGOs, media organizations, financial institutions, activists, ethnic minorities, and high-value individuals, particularly in Middle Eastern and Asian contexts. SpyNote remains one of the most prominent Android malware families used for surveillance, credential theft, extortion, and broader post-compromise device control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.
This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
As a result, malicious services are automatically restarted after the system reboots or are activated upon user interaction, increasing operational reliability while reducing the observable indicators of malicious activity.
SpyNote registers BroadcastReceiver components configured to handle selected system events, including device reboot (BOOT_COMPLETED), screen state changes, power connection events, and USER_PRESENT events indicating device unlock.
Initially, the user is asked to grant access to the Accessibility Service, which represents a critical turning point in the SpyNote operational chain. Once obtained, this permission allows malware to monitor user interactions and simulate input events, enabling further automated privilege escalation.
SpyNote employs a broad range of obfuscation and code protection techniques... Malware extensively leverages encoding mechanisms to conceal critical configuration data, including C2 IP addresses, port numbers, and communication keys.
// HOOK 10: Reflection Calls - Detect hidden API invocations // SpyNote uses reflection to evade static analysis
From a technical standpoint, malware distribution is mainly based on trojanized APK files (Android application installation packages) masquerading as legitimate mobile applications. These are most commonly impersonating web browsers, banking applications, courier services, messaging applications, VPN tools...
In addition, a built-in keylogging module allows the interception of user input, including potentially sensitive authentication data related to banking or corporate applications.
Among the core capabilities of the administrative panel is real-time remote screen viewing, combined with the ability to interact with and control the system interface.
In some variants, additional communication concealment mechanisms were observed, including custom headers, obfuscated session identifiers, or tunnelling over HTTPS...
Once a complete frame is received, the data are decoded and optionally decompressed using the GZIP mechanism before being passed on for further processing.
The final stage of the execution chain involves establishing communication with the C2 infrastructure of the campaign operator. SpyNote initiates outbound network connexions to the configured C2 server...
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SpyNote is discussed as a remote access trojan builder being configured and compiled by the user.
Android remote access trojan that enables full remote device control, accessibility-based keylogging and UI automation, SMS interception and OTP theft, premium-rate SMS fraud, microphone and camera surveillance, GPS tracking, overlay/webinject credential phishing, device administrator abuse for persistence, contact and call log theft, dynamic DEX loading, and anti-analysis checks.
Android remote access trojan that uses raw TCP sockets for C2, leverages reflection to evade static analysis, abuses device admin functions, and stores C2 configuration and tokens in SharedPreferences.
Android malware distributed via deceptive websites mimicking Google Play install pages (as described).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.