SpyAgent is a long-running malware family associated with abuse of legitimate remote-access software on Windows and, in more recent reporting, Android surveillance and credential-theft operations. On Windows, SpyAgent has been tracked under aliases including TeamSpy, TVRat, TeamBot, and Sheldor. It historically abused TeamViewer through DLL search order hijacking and later shifted to hijacking Safib Assistant, modifying or hooking legitimate remote-administration functionality to enable covert operator access while suppressing visible indicators such as logging and user interface elements. Windows variants use DLL side-loading, encrypted configuration data, HTTP-based command-and-control, victim environment fingerprinting, and user-idleness monitoring to help operators act when victims are away from their devices. SpyAgent has also been observed downloading and executing additional malware, including commodity stealers, RATs, and cryptocurrency clippers, indicating a financially motivated intrusion model focused on credential theft, wallet theft, and related post-compromise monetization.
Recent Android SpyAgent variants function as mobile spyware or infostealer implants delivered through trojanized applications and multi-stage droppers. Reported capabilities include abuse of Accessibility Services for screen monitoring, gesture injection, keylogging, and overlay-based credential phishing; interception of SMS messages; theft of contacts; screen capture and recording; camera access; and likely theft of cryptocurrency seed phrases through OCR-assisted collection of screenshots or on-screen wallet data. Android samples have also used persistence and anti-removal mechanisms involving boot receivers, scheduled jobs, alarms, and service-reset logic. Campaign reporting indicates targeting of users in South Korea, India, and Brazil, with lures themed around financial, social-media, telecom, and loyalty applications. Across both Windows and Android activity, SpyAgent is best characterized as a modular surveillance and theft platform used in financially motivated campaigns that combine stealth, social engineering, remote access abuse, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers discovered a critical vulnerability in the Android operating system, dubbed “Pixnapping” and registered under the identifier CVE-2025-48561. This vulnerability allows attackers to reconstruct the screen content of Android devices step by step, thereby extracting sensitive visual information, including private keys, seed phrases, and one-time 2FA authentication codes.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
T1027.001 is a known MITRE technique that adversaries use to decrease the effectiveness of certain tools and detection capabilities that are not designed or configured to scan large files... SpyAgent’s quartz.dll was artificially inflated to the size of 1GB... SpyAgent’s dropper executable was artificially inflated to the size of 700MB.
SpyAgent comes with a config file (.cfg) that contains an encrypted configuration. The bitmap file (.bmp) is used for deriving the key to decrypt the config file.
The idleness monitoring thread monitors pressed keys and selecting or dragging movements. If the user is idle for more than one minute, it sends a sidl(start idle) request... The idleness monitoring thread allows the malware operator to choose the proper time when the victim is not present in order to stay unnoticed.
Value 1 = to_uppercase(crc32( HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid )) Value 2 = to_uppercase(crc32( HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName ))
SpyAgent computes environment hash as an MD5 of the string created by concatenating the following: ... MachineGuid ... ProductName ... user name ... computer name.
The idleness monitoring thread monitors pressed keys and selecting or dragging movements. If the user is idle for more than one minute, it sends a sidl(start idle) request... The idleness monitoring thread allows the malware operator to choose the proper time when the victim is not present in order to stay unnoticed.
The C&C communication thread regularly makes a GET request to <C&C domain>/<C&C path>?id=<9digit number>&stat=<environment hash>.
SpyAgent uses HTTP for command and control <C&C domain>/<C&C path>?id=<9digit number>&stat=<environment hash>.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance malware delivered via a trojanized APK masquerading as the Brazilian loyalty app Clube Leveros. It uses a multi-layer dropper architecture, requests Accessibility permissions, performs screen capture, gesture injection, keylogging, SMS interception, contact theft, camera access, WebView overlay phishing, and is noted for OCR-based cryptocurrency wallet seed phrase theft.
Android malware family described as using image recognition to steal cryptocurrency mnemonic keys/seed phrases.
A remote access malware family that abuses legitimate remote administration tools such as TeamViewer and Safib Assistant via DLL side-loading/hijacking. It obtains the victim's remote-access ID, disables logging, hides the GUI for stealth, uses encrypted configuration data, and communicates with C2 over HTTP. Recent campaigns used oversized padded files and droppers to evade scanning and detection.
An Android detection for a trojanized Coinbase Wallet application that steals wallet seed phrases and sends them to attacker infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.