CypherRAT is an Android remote access trojan and commercialized variant of SpyNote.C that combines device surveillance and remote control with banking credential theft. It provides location tracking, device activity monitoring, SMS and call interception, camera and audio recording, and collection of sensitive information for transmission to attacker-controlled infrastructure. It abuses Android Accessibility Services for keylogging, extracting Google Authenticator codes, automating application installation and updates, and obstructing removal. Banking and popular-application impersonation, including fraudulent login overlays, enables theft of banking, Google, and Facebook credentials. String obfuscation and commercial packing hinder analysis.
CypherRAT was developed and sold by EVLF, a Syria-based malware-as-a-service operator also associated with CraxsRAT. It was marketed through private Telegram channels from August 2021 to October 2022. Its source code became publicly available in October 2022, enabling multiple threat actors to create customized variants and contributing to increased SpyNote-family activity. Malicious applications impersonate banks and familiar services such as Google Play, WhatsApp, and Facebook, principally targeting Android users and financial-service customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“This threat actor is responsible for the development of CypherRAT and CraxsRAT, which in the last 3 years was purchased by over 100 distinct threat actors on a lifetime license.”
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The most recent versions of SpyNote are not only extremely powerful, but they also include a variety of security features, from simple string obfuscation to the use of commercial packers.
SpyNote.C has been the first variant to openly target banking applications, impersonating a large number of reputable financial institutions like HSBC, Deutsche Bank, Kotak Bank, BurlaNubank, as well as others to well-known applications like WhatsApp, Facebook, and Google Play. In addition, we also observed that the attackers utilize more generic application masquerades, such as wallpaper apps, productivity apps, or gaming apps.
Uses Keylogging powered by Accessibility services, to steal banking credentials.
SpyNote also has the capacity to function as a social app credential stealer. This is done by deceiving users into entering their private login information during the login process by launching a webpage with a custom layout that looks a lot like famous services like Gmail and Facebook, much like a traditional overlay attack
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Referenced as a related/precursor RAT family in the lineage leading to BTMOB RAT.
Referenced as an ancestral/related Android RAT family from which BTMOB is assessed to have evolved.
Another Android RAT mentioned as integrated with or related to SpyNote variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.