SpyNote, also tracked as SpyMax and commercialized in some cases as CypherRat, has evolved from Android surveillance malware into a broad financial-theft platform targeting banking and cryptocurrency users through fake apps and social-engineering lures. Researchers linked a major rise in infections to the public leak of CypherRat source code, which enabled multiple actors to rapidly build custom variants impersonating banks, Google Play, WhatsApp, Facebook, and other trusted brands. Across campaigns, the malware abuses Android Accessibility Services to automate installation and updates, resist removal, keylog victims, intercept SMS messages and calls, steal banking credentials, capture Google Authenticator codes, and monitor audio, video, screen activity, and location.
Later samples showed SpyNote operators refining both monetization and evasion. Fortinet reported a crypto-wallet-themed variant that overlaid legitimate wallet apps, replaced destination addresses with attacker-controlled ones, and automated fund transfers, while another sample disguised as an OnlyFans app used a dropper to install a second APK and bypass Android 13 Restricted Settings through a session-based PackageInstaller flow. Regional campaigns in India used fake IRCTC and “Wedding Invitation” APKs spread via WhatsApp to steal OTPs, clipboard data, notifications, contacts, and banking information, with researchers also noting malformed APK structures, packing, anti-emulation checks, and compressed command-and-control traffic designed to frustrate reverse engineering and prolong infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Fortinet reported that the February 2024 SpyNote sample used Accessibility abuse to detect legitimate wallet apps, display a fraudulent overlay, replace the destination wallet address with an attacker-controlled one, and automatically initiate transfers. The APK also used a malformed structure as an anti-analysis technique and was detected as Android/SpyNote.F!tr.
On February 1, 2024, Fortinet researchers found a malicious Android sample posing as a legitimate cryptocurrency wallet that contained SpyNote RAT. The sample targeted users of mobile crypto wallet or banking apps and aimed to steal funds.
Fortinet says that since 2023, SpyNote activity has shown growing interest in financial institutions. This reflects the malware family's evolution from general surveillance toward banking and financial theft use cases.
After the leak, multiple actors quickly built CypherRat-derived campaigns that impersonated banks such as HSBC and Deutsche Bank, as well as apps like Google Play, WhatsApp, and Facebook. The newer SpyNote.C variant was described as openly targeting banking applications.
In October 2022, the CypherRat/SpyNote.C source code was leaked and then made publicly available on GitHub after scamming incidents on hacking forums. The public release enabled broader reuse by other threat actors.
ThreatFabric observed a sharp increase in SpyNote detections and samples in the last quarter of 2022 following the October 2022 source-code release. The post-leak growth included rapid creation of custom variants and more than 1,100 SpyNote/CypherRat samples collected from October 2022 onward.
ThreatFabric and BleepingComputer report that SpyNote.C was commercialized as CypherRat and sold to individual actors through private Telegram channels, with payments handled through Sellix and cryptocurrencies. The sales period is described as running from August 2021 until October 2022 and reaching more than 80 customers.
Fortinet states that the SpyNote Android remote access trojan first surfaced in 2020, marking the earliest origin point mentioned for the malware family in the references.
K7 Labs documented a phishing campaign targeting Indian Android users with a fake Wedding Invitation APK delivered through WhatsApp. The SpyMax malware installed a second app, abused Accessibility and SMS-related permissions, stole OTPs and other sensitive data, and communicated with 104.234.167[.]145 over TCP port 7860.
Cryptax analyzed a SpyNote campaign disguised as an OnlyFans app that installed an embedded child APK via a session-based PackageInstaller flow to bypass Android 13 Restricted Settings. The child APK was malformed to break common reverse-engineering tools and unpacked to an obfuscated SpyNote payload communicating with 95.174.67.245:7744.
K7 Labs reported a SpyNote Android RAT campaign impersonating the IRCTC app and distributed via WhatsApp using a malicious irctcconnect.apk link. The malware repeatedly sought Accessibility permissions, logged keystrokes, collected location data, and exfiltrated compressed data to online[.]spaxdriod[.]studio at 154.61.76[.]99.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
support.google.com
Open sourcelabs.k7computing.com
Open sourcecryptax.medium.com
Open sourcefortinet.com
Open sourcelabs.k7computing.com
Open sourcebleepingcomputer.com
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.