SpyNote, also known as SpyMax, is an Android remote access trojan and spyware family used for surveillance, credential theft, and financial fraud. Its configurable builder enables operators to generate malicious applications that impersonate legitimate banking, messaging, productivity, public-health, and cryptocurrency-wallet apps. SpyNote has been used in criminal campaigns and targeted espionage, including modified Android payloads associated with Confucius and attacks against high-value individuals in Southern Asia.
SpyNote provides remote control over infected devices and can collect SMS messages, contacts, call logs, files, device identifiers, and location information. It supports screen capture, camera and audio recording, and transmission of stolen information to attacker-controlled infrastructure. Abuse of Android Accessibility Services enables monitoring of on-screen activity, keylogging, automated interface interaction, installation and updating of additional applications, and interference with uninstallation. Variants steal banking and social-media credentials through keylogging and fraudulent login overlays, intercept SMS authentication codes, and extract codes from Google Authenticator. Some cryptocurrency-focused samples manipulate wallet transfer forms and automatically initiate transfers to attacker-controlled accounts.
The malware conceals its application icon, continues operating in the background, and uses foreground services to maintain execution. String obfuscation, commercial packing, and malformed Android application packages impede analysis. Distribution includes phishing websites, messaging services such as WhatsApp, deceptive application lures, and telephone-based social engineering. SecuriDropper has delivered SpyNote through an installation mechanism that bypasses Android 13 Restricted Settings, allowing the payload to request sensitive accessibility permissions.
SpyNote.C, commercialized as CypherRat, expanded the family’s banking-focused functionality. Its source-code release in October 2022 contributed to increased detections and proliferation of customized variants. In financial-fraud campaigns targeting victims in Czechia, Slovakia, and Slovenia, attackers have used SpyNote’s accessibility-based remote control to silently install and activate WindRelay NFC-relay malware. SpyNote supplies device takeover in this attack chain; WindRelay performs the payment-card relay.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spynote – Commercially available Android RAT (cracked versions available)
A large portion of the malicious applications are SpyNote samples... Of the malicious applications in this campaign, 64 of 71 are SpyNote samples, a well known commercial surveillanceware family.
In addition to their custom-made malware, this group also utilized publicly available Android malware called SpyNote which had more functionality including remote device access and the ability to monitor calls.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
An example of a long-standing and continuously evolving threat in this domain is the SpyNote malware, also known under related names such as CypherRat and SpyMax. SpyNote is a Remote Access Trojan (RAT) family that has been present in the mobile threat landscape for several years.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
Group-IB documented a previously unseen Android NFC relay malware family it tracks as WindRelay, deployed alongside the SpyNote remote access trojan (RAT) in live-call social engineering against victims in Czechia, Slovakia, and Slovenia.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
The most recent versions of SpyNote are not only extremely powerful, but they also include a variety of security features, from simple string obfuscation to the use of commercial packers.
Their use of a bank subdomain suggests that these files impersonated the victim bank’s mobile banking application.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
The following code recognizes the use of a legitimate crypto wallet and displays an overlay over it. The injected overlay consists of a WebView whose HTML is hard-coded in Base64. | For example, the malicious sample uses the Accessibility API to record device unlocking gestures.
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
SpyNote and SpyMax are a variety of Android malware and are, as their names suggest, spyware. They can surveil and steal data, including login data (such as username and password combinations and two-factor authentication codes) from infected Android devices.
The following code recognizes the use of a legitimate crypto wallet and displays an overlay over it. The injected overlay consists of a WebView whose HTML is hard-coded in Base64. | For example, the malicious sample uses the Accessibility API to record device unlocking gestures.
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
In a report published August 12, 2026, the firm said it identified 23 samples uploaded to VirusTotal between November 2025 and July 2026 and four command-and-control (C2) IP addresses.
Use the Camera API to record and send videos from the device to the C2 server
"[Attackers] remotely deploy WindRelay without additional user interaction."
"WindRelay, a new Android NFC relay malware deployed alongside the SpyNote remote access trojan" and "remote access can facilitate additional financial fraud."
MITRE ATT&CK Tactics Techniques Defense Evasion Application Discovery Obfuscated Files or Information, Virtualization/Sandbox Evasion Discovery Security Software Discovery, System Information Discovery Collection Email Collection, Data from Local System Command and Control Encrypted Channel, NonStandard Port
186 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access trojan used to gain control of victims' devices, facilitate financial fraud, and deploy WindRelay without further user interaction.
Android remote-access trojan used as the initial payload to control the victim device and install the NFC-relay malware without further victim interaction.
Remote access trojan used alongside WindRelay to gain Accessibility Service permissions, enabling silent installation and activation of the NFC relay malware via social-engineering-driven remote device access.
A remote access trojan used alongside WindRelay in live-call social engineering campaigns targeting victims in Central Europe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.