TF-MAL-apk.spynote
📛 Threat Title
Malware family: SpyNote
Description
ThreatFox malware family `apk.spynote`. Printable name: SpyNote. Aliases: CypherRat.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.spynote
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spynote
IOC database
- Type
- domain
- Value
apk.spynote- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.spynote
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spynote
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
SpyNote , also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023-2025.
-
web:blog.netmanageit.com
Continuous monitoring of malware delivery domains, rapid sample sharing across intel platforms, and enhanced mobile endpoint protection are essential countermeasures. By integrating these insights into detection rules and user-education campaigns, organizations can mitigate the risks posed by SpyNote and similar Android malware families.
-
web:cybersecuritynews.com
This advanced variant of the SpyMax/ SpyNote family targets Chinese-speaking users across mainland China and Hong Kong, exploiting Android Accessibility Services through polished social engineering techniques and deceptive UI elements to gain near-total control of victims' devices.
-
web:dti.domaintools.com
This report highlights the resurfacing of SpyNote activity by the same actor in a previous DTI report and provides additional information around the recent activity and changes in tactics since the prior report.
-
web:eln0ty.github.io
SpyNote Malware C2 Emulator 5 minute read On this page Introduction Why It Matters Espionage Features Remote Control AndroidManifest.xml InitializeService Utilities Privilege Escalation C2 Connection Full Code Conclusion Introduction SpyNote (aka SpyMax) is a remote access trojan long known for its ability to harvest sensitive data from compromised Android devices by abusing accessibility ...
-
web:hunt.io
SpyNote is an Android malware that acts as a Remote Access Trojan (RAT). It gives attackers full control over infected devices. It can intercept messages, access data and control device functions like camera and microphone. Its sneaky nature makes users install it unknowingly and that's a big security risk.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.
-
web:medium.com
The cumulative application of these techniques significantly impedes both static analysis and behavioural detection of SpyNote , underscoring the increasing sophistication of this malware family ...
-
web:motasem-notes.net
This article provides an analysis of the SpyNote Android spyware variant, utilizing the ANY.RUN interactive malware analysis service. SpyNote is presented as a potent threat with extensive capabilities beyond simple spying. These include collecting SMS messages, logging keystrokes, capturing the device screen, and enabling on-device fraud. Notably, it can overlay fake user interfaces, often ...
-
web:www.cyfirma.com
Introduction SpyNote , a notorious Android malware , has evolved into a highly advanced threat, capable of extensive control over infected devices. This report provides an in-depth analysis of the malware's functionalities, based on code analysis and real-time execution observations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.