SpyMax is an Android remote-access trojan and commercial surveillance framework, often described as a successor or evolution of SpyNote. It enables operators to remotely monitor and control compromised Android devices, collect private data, and exfiltrate it to command-and-control infrastructure. Documented capabilities include SMS and notification interception, contact and call-log collection, location tracking, camera and microphone capture, audio recording, access to stored photos and files, account and installed-application enumeration, keylogging, clipboard collection, and execution of operator commands. Some deployments use Android Accessibility permissions to capture user input and notifications, including banking one-time passwords and two-factor authentication codes, supporting banking fraud and credential theft. SpyMax-based applications can maintain execution after reboot, conceal their launcher icon, and masquerade as legitimate applications. Campaigns have used themed Android application lures, including financial-aid, football-club, live-streaming, and wedding-invitation themes, and have been distributed through messaging platforms and deceptive application-download pages. SpyMax has been used in campaigns targeting Android users in India, Tanzania, and Syria; a documented Syria-focused operation used a financial-aid lure to target Syrian military personnel. Its builder-style ecosystem enables operators to generate customized APKs with chosen icons and command-and-control settings.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
To hide its malicious code from scrutiny, the latest versions of SpyNote employ string obfuscation and use commercial packers to wrap the APKs. Moreover, all information exfiltrated from SpyNote to its C2 server is obfuscated using base64 to hide the host.
Their use of a bank subdomain suggests that these files impersonated the victim bank’s mobile banking application.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
Use keylogging powered by Accessibility services to steal banking credentials.
SpyNote and SpyMax are a variety of Android malware and are, as their names suggest, spyware. They can surveil and steal data, including login data (such as username and password combinations and two-factor authentication codes) from infected Android devices.
These apps are basically spyware, which include the following capabilities: ... Read/write external storage Steal photos
Use keylogging powered by Accessibility services to steal banking credentials.
We analyzed the C&C command ‘info’ and the associated APK. This command collects the clipboard and SMS data
the app hides itself from the victim and plays it's hideous activities of spying on the user and sending all the stolen data back to the attacker
Use the Camera API to record and send videos from the device to the C2 server
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT/spyware family identified in the content as the lineage from which CraxsRAT developed after a 2020 source-code leak.
Android spyware/stalkerware framework used to build fake football-themed apps that hide themselves after launch, spy on victims, and exfiltrate stolen data. The samples were described as capable of reading SMS messages, fetching contacts, recording audio, making calls, accessing real-time location, reading/writing external storage, stealing photos, and accessing the camera.
Android spyware/Trojan builder framework referenced as similar to the analyzed TikTok Pro sample and likely related in functionality or lineage.
Android remote access trojan used to remotely control infected devices; referenced here in the context of training cybercriminals on deployment and use.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.