CypherRat is an Android malware family and commercialized variant within the SpyNote/SpyMax ecosystem. It is best characterized as an Android remote access trojan that combines SpyNote’s surveillance and device-control functions with banking-trojan-style credential theft. The malware has been associated with sale and distribution through criminal channels, including Telegram, and its public source-code leak in late 2022 contributed to rapid proliferation of forks and custom campaigns by multiple actors.
CypherRat provides remote access to compromised Android devices and supports broad monitoring of device activity and status. Reported capabilities include GPS and network-based location tracking, interception of SMS messages and phone calls, collection of audio and video recordings, camera abuse, and theft of social-media and account credentials. Variants in the same lineage abuse Android Accessibility Services extensively to automate installation and update actions, hinder removal, keylog user input, extract one-time codes from authenticator applications, and harvest banking credentials. Campaigns have also used impersonation of financial institutions and popular consumer applications to facilitate credential theft.
Operationally, CypherRat reflects the convergence of Android spyware and banking malware. It has been used to target banking users through fake or impersonating applications and overlays, while retaining full RAT-style surveillance and control features. Following the leak of its codebase, threat actors quickly adapted it into customized Android campaigns, increasing its prevalence and making SpyNote-derived malware a persistent threat to mobile users, particularly those using banking and other sensitive applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BTMOB is assessed to be an evolution of CraxsRAT, CypherRAT, and SpySolr families..."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The most recent versions of SpyNote are not only extremely powerful, but they also include a variety of security features, from simple string obfuscation to the use of commercial packers.
SpyNote.C has been the first variant to openly target banking applications, impersonating a large number of reputable financial institutions like HSBC, Deutsche Bank, Kotak Bank, BurlaNubank, as well as others to well-known applications like WhatsApp, Facebook, and Google Play. In addition, we also observed that the attackers utilize more generic application masquerades, such as wallpaper apps, productivity apps, or gaming apps.
Uses Keylogging powered by Accessibility services, to steal banking credentials.
SpyNote also has the capacity to function as a social app credential stealer. This is done by deceiving users into entering their private login information during the login process by launching a webpage with a custom layout that looks a lot like famous services like Gmail and Facebook, much like a traditional overlay attack
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT family referenced as a predecessor/successor lineage related to BTMOB.
Referenced as a related/precursor RAT family in the lineage leading to BTMOB RAT.
Referenced as an ancestral/related Android RAT family from which BTMOB is assessed to have evolved.
Another Android RAT mentioned as integrated with or related to SpyNote variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.