SpyNote RAT is an Android remote access trojan used for surveillance and data theft on compromised mobile devices. It is associated with the SpyNote/SpyMax malware lineage, and SpyMax variants have been reported as derived from leaked SpyNote source code. The malware is designed to provide remote operators with broad access to victim devices, including the ability to read SMS messages, access contact information, activate the device microphone, and copy files from the device to command-and-control infrastructure. These capabilities make it suitable for both espionage-oriented monitoring and general post-compromise collection.
On infected Android devices, SpyNote RAT can maintain persistence by registering an Android broadcast receiver that automatically starts the malware when the device boots. This event-triggered execution mechanism allows the implant to resume operation after reboot without requiring user interaction. Its use of standard Android platform features for startup persistence is consistent with common mobile malware tradecraft and can complicate user-visible detection.
SpyNote RAT targets the Android platform and fits the broader class of mobile surveillance malware that abuses device permissions and local data access to harvest sensitive information. High-confidence observed behaviors include SMS collection, contact access, microphone activation for audio capture, and exfiltration of files from local storage. These functions position it as a multifunctional Android RAT focused on persistent remote monitoring and theft of user data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan referenced as the leaked codebase underlying SpyMax variants; used for spyware and sometimes banking-trojan scenarios per the report.
Android remote access trojan that exfiltrates files to command-and-control infrastructure.
Android remote access trojan that auto-starts on boot using a broadcast receiver.
Android RAT that reads SMS messages from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.