s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.spynote

📛 Threat Title

Malware family: SpyNote

Category: SpyNote First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.spynote`. Printable name: SpyNote. Aliases: CypherRat.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.spynote VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spynote

IOC database

Type
domain
Value
apk.spynote
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.spynote

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spynote

References (1)

Remediations (10)

  • web:any.run

    SpyNote , also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023-2025.

  • web:blog.netmanageit.com

    Continuous monitoring of malware delivery domains, rapid sample sharing across intel platforms, and enhanced mobile endpoint protection are essential countermeasures. By integrating these insights into detection rules and user-education campaigns, organizations can mitigate the risks posed by SpyNote and similar Android malware families.

  • web:cybersecuritynews.com

    This advanced variant of the SpyMax/ SpyNote family targets Chinese-speaking users across mainland China and Hong Kong, exploiting Android Accessibility Services through polished social engineering techniques and deceptive UI elements to gain near-total control of victims' devices.

  • web:dti.domaintools.com

    This report highlights the resurfacing of SpyNote activity by the same actor in a previous DTI report and provides additional information around the recent activity and changes in tactics since the prior report.

  • web:eln0ty.github.io

    SpyNote Malware C2 Emulator 5 minute read On this page Introduction Why It Matters Espionage Features Remote Control AndroidManifest.xml InitializeService Utilities Privilege Escalation C2 Connection Full Code Conclusion Introduction SpyNote (aka SpyMax) is a remote access trojan long known for its ability to harvest sensitive data from compromised Android devices by abusing accessibility ...

  • web:hunt.io

    SpyNote is an Android malware that acts as a Remote Access Trojan (RAT). It gives attackers full control over infected devices. It can intercept messages, access data and control device functions like camera and microphone. Its sneaky nature makes users install it unknowingly and that's a big security risk.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.

  • web:medium.com

    The cumulative application of these techniques significantly impedes both static analysis and behavioural detection of SpyNote , underscoring the increasing sophistication of this malware family ...

  • web:motasem-notes.net

    This article provides an analysis of the SpyNote Android spyware variant, utilizing the ANY.RUN interactive malware analysis service. SpyNote is presented as a potent threat with extensive capabilities beyond simple spying. These include collecting SMS messages, logging keystrokes, capturing the device screen, and enabling on-device fraud. Notably, it can overlay fake user interfaces, often ...

  • web:www.cyfirma.com

    Introduction SpyNote , a notorious Android malware , has evolved into a highly advanced threat, capable of extensive control over infected devices. This report provides an in-depth analysis of the malware's functionalities, based on code analysis and real-time execution observations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.