SpyNote, also known as SpyMax, is an Android remote-access trojan and spyware family active since at least 2020. It abuses Android Accessibility Services to enable remote device interaction, automate interface actions, install or update applications, impede removal, keylog users, and capture authentication codes. SpyNote variants can collect and transmit SMS messages, call-related data, screen captures, audio or video recordings, location information, device details, and credentials harvested through impersonated banking, social-media, and other popular applications. SpyNote.C, also marketed as CypherRat, expanded the family’s financial-fraud functionality through banking-application impersonation, credential theft, and theft of multi-factor authentication codes. Its source-code leak in 2022 contributed to widespread derivative activity. Some variants have targeted cryptocurrency users by overlaying wallet applications and using Accessibility-driven automation to substitute attacker-controlled recipient addresses and initiate transfers. SpyNote is commonly delivered through phishing sites, deceptive applications, third-party distribution channels, and telephone-based social engineering. It has also been deployed through SecuriDropper to bypass Android 13 Restricted Settings protections. In contactless-payment fraud operations reported from Central Europe, attackers used SpyNote remote access to silently deploy WindRelay NFC-relay malware after persuading victims to install a personalized malicious application. SpyNote has also appeared in espionage activity attributed to Confucius and ITG18.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spynote – Commercially available Android RAT (cracked versions available)
A large portion of the malicious applications are SpyNote samples... Of the malicious applications in this campaign, 64 of 71 are SpyNote samples, a well known commercial surveillanceware family.
In addition to their custom-made malware, this group also utilized publicly available Android malware called SpyNote which had more functionality including remote device access and the ability to monitor calls.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
Group-IB documented a previously unseen Android NFC relay malware family it tracks as WindRelay, deployed alongside the SpyNote remote access trojan (RAT) in live-call social engineering against victims in Czechia, Slovakia, and Slovenia.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
The most recent versions of SpyNote are not only extremely powerful, but they also include a variety of security features, from simple string obfuscation to the use of commercial packers.
Their use of a bank subdomain suggests that these files impersonated the victim bank’s mobile banking application.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
The following code recognizes the use of a legitimate crypto wallet and displays an overlay over it. The injected overlay consists of a WebView whose HTML is hard-coded in Base64. | For example, the malicious sample uses the Accessibility API to record device unlocking gestures.
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
SpyNote and SpyMax are a variety of Android malware and are, as their names suggest, spyware. They can surveil and steal data, including login data (such as username and password combinations and two-factor authentication codes) from infected Android devices.
The following code recognizes the use of a legitimate crypto wallet and displays an overlay over it. The injected overlay consists of a WebView whose HTML is hard-coded in Base64. | For example, the malicious sample uses the Accessibility API to record device unlocking gestures.
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
In a report published August 12, 2026, the firm said it identified 23 samples uploaded to VirusTotal between November 2025 and July 2026 and four command-and-control (C2) IP addresses.
Use the Camera API to record and send videos from the device to the C2 server
"[Attackers] remotely deploy WindRelay without additional user interaction."
"WindRelay, a new Android NFC relay malware deployed alongside the SpyNote remote access trojan" and "remote access can facilitate additional financial fraud."
MITRE ATT&CK Tactics Techniques Defense Evasion Application Discovery Obfuscated Files or Information, Virtualization/Sandbox Evasion Discovery Security Software Discovery, System Information Discovery Collection Email Collection, Data from Local System Command and Control Encrypted Channel, NonStandard Port
186 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access trojan used to gain control of victims' devices, facilitate financial fraud, and deploy WindRelay without further user interaction.
Android remote-access trojan used as the initial payload to control the victim device and install the NFC-relay malware without further victim interaction.
Remote access trojan used alongside WindRelay to gain Accessibility Service permissions, enabling silent installation and activation of the NFC relay malware via social-engineering-driven remote device access.
A remote access trojan used alongside WindRelay in live-call social engineering campaigns targeting victims in Central Europe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.