Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 4 actors

SpyNote

SpyNote is an Android remote access trojan (RAT) / spyware family, also referred to in the content alongside SpyMax, with variants detected as Trojan-Spy.AndroidOS.SpyNote.* and Android.SpyMax. It is described as a paid or commercially available Android RAT whose source code has also been reused to produce related variants such as SpyMax, Crax RAT, and Eagle Spy. The malware is commonly disguised as legitimate Android applications and delivered through fake apps, social media posts, messaging platforms such as WhatsApp and Telegram, phishing pages, unofficial sources, and in some cases infrastructure hosted on Proton66/PROSPERO-linked networks. One reported campaign active since at least March 2020 distributed SpyNote and 888 RAT via dedicated Facebook profiles targeting the Kurdish ethnic group; another targeted high-value individuals in Southern Asia via WhatsApp-delivered payloads. SpyNote-based APKs were also noted as likely related to targeting of Tibetan individuals and organizations, and prior reporting cited use by groups including OilRig/APT34, APT-C-37, OilAlpha, and BladeHawk. The content also notes broader Android targeting of government agencies, NGOs, media organizations, financial institutions, activists, and mobile users in multiple regions.

Capabilities directly described in the content include full remote control of infected Android devices; collection of device information such as IMEI, IMSI, SIM and network details; access to contacts, SMS, call logs, files, and precise location; camera access; microphone/audio recording; screenshot capture; monitoring of incoming and outgoing calls; accessibility-service abuse for on-screen monitoring, keylogging, UI automation, and hindering app removal; overlay-based credential phishing and OTP theft; SMS interception including banking one-time passwords; SMS sending and premium-rate SMS fraud; dynamic code loading; reflection-based evasion; emulator/anti-analysis checks; and device administrator abuse including screen lock, password reset, and attempted wipe functionality. The content further states that SpyNote uses raw TCP sockets for command-and-control and stores C2 configuration and tokens in SharedPreferences.

High-confidence indicators and examples mentioned in the content include the C2 IP 182.191.122.219 from a Southern Asia-targeted SpyNote case; Android package elimination.kitchen.secured and app name GoosApp identified as SpyNote/SpyMax; hashes including SHA-256 7129d6c57182f4e53a4fd0f6aac15de30ffc5bfa34bc639a19ee39d2856b3c07 and MD5 b2c5e29222f57cf91d30d37b8ec54cc3 for that sample; certificate SHA-256 465983f7791f2abeb43ea2cbdc7f21a8260b72bc08a55c839fc1a43bc741a81e; receiver elimination.kitchen.AdminReceiver; and four additional SHA-256 values from the CYFIRMA case: 8AA1A66E03596C0EBA6F91FB081DDB4081F43B02D421E069C6BE8BBF5D399B89, 0552137AAA2C9419C8843D50BCB15A4C80913ED47EB71C5E5AB9B5AC257944ED, 6127DAF756865EE089BA83EFDADEBDA2C047026A698759DE09127D0DFE630E8D, and A70089301FF628F09B90B269F6E8F5C6B5AE0B3073028ABCC62FEC9D2F1C954C. The content also notes that SpyNote has been prevalent in mobile threat telemetry, with multiple variants appearing among top Android malware verdicts, and that it has been used for surveillance, extortion, and identity theft.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
OilRig

This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.

via cyfirma othercyfirma.com
OilAlpha

This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.

via cyfirma othercyfirma.com
APT-C-37

This sample, attributed to an unknown threat actor, was generated using the Spynote Remote Administration Tool.

via cyfirma othercyfirma.com
BladeHawk

This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps.

via eset welivesecurity blogwelivesecurity.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Privilege Escalation

1 technique
T1548Abuse Elevation Control MechanismEvidence1

// HOOK 11: Device Admin - Detect admin privilege abuse

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence1

"dynamic payload decryption and DEX element injection... control flow and identifier obfuscation applied to the C2 logic"

T1027.007Dynamic API ResolutionEvidence1

// HOOK 10: Reflection Calls - Detect hidden API invocations // SpyNote uses reflection to evade static analysis

T1036MasqueradingEvidence1

the user received a phishing link to download malware disguised as a shipment tracking app.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

// HOOK 9: Network Connections - Capture C2 communications // SpyNote uses raw TCP sockets for C2

T1219Remote Access ToolsEvidence1

The SpyNote RAT was occasionally used as the malware dropper and NFC activator.

Impact

2 techniques
T1485Data DestructionEvidence1

console.log(' [ADMIN] CRITICAL : wipeData () called! Device wipe attempted! Flags : ' + flags);

T1565Data ManipulationEvidence1

// HOOK 12: SharedPreferences - Capture config/token storage // SpyNote stores C2 config and tokens in SharedPreferences

INDICATORS OF COMPROMISE

IOCs tracked for this family

40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
9 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
27 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
ip.v4●●●●●●●●●●●●View more in app2 years ago
ACTIVITY FEED

Recent activity

16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching40

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.