Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Spynote

129
Global rank
140 infographic chevron month
Month rank
174 infographic chevron week
Week rank

SpyNote, also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023–2025.

RAT
Type
Unknown
Origin
1 June, 2016
First seen
28 September, 2026
Last seen
Also known as
SpyMax
CypherRat

How to analyze Spynote with ANY.RUN

RAT
Type
Unknown
Origin
1 June, 2016
First seen
28 September, 2026
Last seen

IOCs

IP addresses
94.141.122.123
142.251.127.81
142.251.154.119
142.251.150.119
142.251.157.119
195.189.240.74
142.251.156.119
142.251.20.94
216.239.35.12
142.251.151.119
192.178.183.139
195.189.240.75
142.251.152.119
142.251.13.94
142.251.20.138
142.251.153.119
216.239.35.8
13.226.247.39
142.251.110.101
64.233.166.81
Hashes
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
08a541ca21a32ea018ef5945865575c036645a638ab7c13760a67bafef622ae8
05eb191d722cc8e45733cda6a36876fc4403eee237f0570094d0940a73b8ea8c
f2590620465eb057a780aaefa352536fe2120192f6d1d8427bb82192ac3b22a1
bcbb86ddb124f146250fe195adfff45d71788c47fe437b6e64f0229102e740a5
d97d5230d038251cc3fc83273230ffee4f16fdd03591fa5ef0f3e70750a81bd6
f50fde46412dbc5c16178e8d7993bc483ac2dd0c320bf227583a86b74502e984
29f20393c77eec9b7888848815d2fa10df5e967fb76923b7e42829f5ab1a87c8
551b242834fdf406b16c4e112d649740676538561cf2cb87b8d1cde92cf39df1
4b3dec671826e4f9dd6f846fea87a3d363abcd86a292a5f14dbfaa52a56ca44b
5b74e51685daf429d89da8ebef83ea9eccb67feca81463056bf55000d2155380
ea7f29bff4184d3a02a12a038f570bfcaac8028d856a0fca23a0118c48003e17
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
a93bb698ab8467398582fd7fd9bc2287399cbb8a0763ed63d24806b1fc7f1b0e
d4d2f02a9ac006af58a00baea24197c3d0549f8889c8158c39034b6075a81aec
97a11825713db7a9355024a3632bb2b6b1a930133e4e871cfe775ca8e3e3239e
40182e418310cc4c3373c261551d015129fc6311ea20a32898796130d3e0961e
4636f96b3b70af97e7e2b401c4af3e2fe1d941c0ca0e8bcfd5cbfa0bb5b2e7cf
e59789dea90bf3c49c4262dad2d9cd868c3b5fae65615658a4261518f72171f6
Domains
connectivitycheck.gstatic.com
update.googleapis.com
www.google.com
time.android.com
clientservices.googleapis.com
diia.gov.ua
google.com
staging-remoteprovisioning.sandbox.googleapis.com
m.stripe.com
d26b395fwzu5fz.cloudfront.net
static-fonts-css.strikinglycdn.com
uploads.strikinglycdn.com
static-assets.strikinglycdn.com
p.typekit.net
static-fonts.strikinglycdn.com
cdnjs.cloudflare.com
m.stripe.network
182.49.198.154.in-addr.arpa
happypiggy.mystrikingly.com
api.keen.io
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabooc7nzmbilsty9swfkrusfhgy3gl4u_hgre=&request_id=17c35b6a-02e4-48cc-8395-2f0623dd4aa9
https://update.googleapis.com/service/update2/json?cup2key=15:m0jj7zaxnf-b1xajjdud8v5sttgsfejr4cuzwjm0hwa&cup2hreq=de1835f9bd29e5512b1af5eaa26f0b0e67540127aa703a77b79f2816833f79cc
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabojtjxkobilsty7njd31ckxmpzdvs9hdf9bi=&request_id=d66a08e0-e878-4a79-9f91-2e77695d1fc7
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboivbfd0bilstyxjxdgy9rk0gfwnesq973es=&request_id=551dbbed-6032-4100-ac75-f371d9bfad73
https://update.googleapis.com/service/update2/json?cup2key=15:enjmewrndmexlj0modujbcfij5skqsopzgiyenryy8y&cup2hreq=7db2b167a8dff95e97ea14ef09cdd5c403550a212493ac8eaaeff72f7b234a66
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://happypiggy.mystrikingly.com/
https://static-fonts-css.strikinglycdn.com/css?family=playfair+display:400,700,400italic,700italic|playfair+display+sc:regular,italic,700,700italic,900,900italic|montserrat:400,700&subset=latin,latin-ext&display=swap
https://static-assets.strikinglycdn.com/themes/s5-theme/main_v4.53f4fd74d72bc3e5c93f.bundle.css
https://static-assets.strikinglycdn.com/images/fb_images/default.png
https://static-assets.strikinglycdn.com/detectie-c385c24313ef0e9e4e7a1e131bf5e59f0fbd468f9f9ef44fd6739ae84ef0c0a4.js
https://static-assets.strikinglycdn.com/images/ecommerce/ecommerce-footer-logo.png
https://static-assets.strikinglycdn.com/i18n-2ace11ac644d0b40fb8b7cb65e9dd1e553022750e0254118dacbe1fe50735e97.js
https://static-assets.strikinglycdn.com/webpack/lightboostedpage-site-bundle.4ac6ea1bdb388e4a88b9.js
https://custom-images.strikinglycdn.com/res/hrscywv4p/image/upload/c_limit,fl_lossy,h_300,w_300,f_auto,q_100/13403996/512140_449643.png
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 1389
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 3845
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 5997
comments 0

What is SpyNote malware?

SpyNote (aka SpyMax and CypherRat) is a Remote Access Trojan (RAT) designed for Android devices. It evades detection while maintaining persistent access and provides attackers with extensive control over infected devices, enabling:

  • Keylogging
  • Screen recording & screenshots
  • Call & SMS interception
  • Microphone & camera activation
  • File theft & remote execution
  • GPS tracking
  • App manipulation (uninstalling security apps).

SpyNote primarily spreads through social engineering tactics, exploiting user trust to install the malware on Android devices. Its infiltration methods include phishing and smishing campaigns when users receive malicious emails and text messages posing as legitimate communications from banks, service providers, or trusted entities, urging users to download fake apps or updates. For example, campaigns have mimicked Italian government alerts or antivirus software. Other examples included SpyNote posing as critical services, such as power or water suppliers, to create urgency and prompt immediate installation.

Targeted attacks, especially against high-value individuals in South Asia, have used WhatsApp to deliver SpyNote payloads disguised as legitimate files. This malware has been hosted on deceptive websites mimicking legitimate platforms, such as Google Play Store pages or antivirus software sites (e.g., fake Avast Mobile Security)

SpyNote has been caught impersonating trusted applications, such as banking apps (e.g., HSBC, Deutsche Bank), system updates, productivity tools, and games. This trojan is frequently distributed through unofficial app stores or sideloaded APKs, bypassing Google Play’s security checks.

Read about Salvador Stealer, another Android threat abusing mobile banking

Once installed, SpyNote requests permissions, particularly Accessibility Services, which it abuses to grant itself additional permissions without user intervention, ensuring deep access to the device.

Besides exfiltrating sensitive data (SMS messages, call logs, contacts, GPS location, files, photos, credentials), SpyNote captures keystrokes and screenshots and activates the microphone and camera to record audio, phone calls, or videos. It allows attackers to initiate transactions and execute arbitrary commands. It can also install additional apps or malware, update itself, or uninstall apps to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

SpyNote RAT’s Prominent Features

SpyNote is especially notable and dangerous due to its versatility and targeting of sensitive data and sectors:

  • Financial Sector: Targets banking apps (e.g., HSBC, Deutsche Bank, Bank of America) to steal credentials, perform on-device fraud, or bypass 2FA, leading to financial losses. Recent variants focus on cryptocurrency wallets, enabling unauthorized transfers.
  • Critical Infrastructure and Services: Poses as essential service providers (e.g., power, water, or emergency alerts) to exploit user urgency, potentially disrupting trust in legitimate services.
  • High-Value Targets: Used by APT groups to spy on government agencies, NGOs, media organizations, and activists, particularly in South Asia. Campaigns have targeted Indian defense personnel and other high-profile individuals.
  • Widespread Accessibility: Source code leaks (e.g., CypherRat in October 2022) have made SpyNote widely available on darknet forums and Telegram, enabling independent actors and organized groups to deploy custom variants. Variants like SpyNote.A, SpyNote.B, SpyNote.C, SpyMax, Crax RAT, and Eagle Spy continue to evolve with enhanced capabilities.
  • Persistence: Its ability to resist uninstallation and survive reboots makes it a long-term threat, often requiring a factory reset, which results in data loss.

SpyNote’s Execution Process and Technical Details

ANY.RUN’s Interactive Sandbox supports the analysis of APK files and enables the research of Android malware, so we can watch SpyNote in action after detonating its APK disguised as an app of the Spanish BBVA Bank in the safe VM environment.

View the analysis session

SpyNote’s execution chain starts with deceptive distribution. Operators clone Google Play pages or send SMS phishing links that claim you need a popular app update or mobile‑banking tool. Tapping the “Install” or “Download” button triggers a short JavaScript snippet that silently drops a tampered APK — often branded with a convincing name and icon like “BBVA Prime” in our case — onto the device.

SpyNote malware analysis in ANY.RUN A sample of SpyNote detonated inside ANY.RUN's Interactive Sandbox

When the user opens the app, SpyNote asks for permissions such as Accessibility Service access. Granting that single request is enough: using Accessibility, the malware auto‑clicks its way through every subsequent dialogue to secure dangerous privileges — including reading and sending SMS, recording audio, taking photos, accessing contacts, call logs, and external storage — without showing more pop‑ups.

To avoid discovery, SpyNote immediately hides its icon from the launcher and recent‑apps screen. The implant can then be awakened by several triggers: receipt of certain SMS commands, an outgoing phone call, a visit to a specific URL, or an auxiliary “launcher” dropper that sends an explicit intent. Once active, it establishes an encrypted channel to hard‑coded command‑and‑control servers for tasking and data exfiltration.

Capabilities are extensive: intercepting and forwarding 2FA codes, logging keystrokes, capturing screenshots, recording calls, activating the microphone and both cameras, tracking GPS, and silently downloading further payloads. If the victim opens Settings or long‑presses the app in an attempt to uninstall, SpyNote leverages the same Accessibility control to close those windows or quickly restart its own service, making removal nearly impossible without booting into safe mode or using ADB.

Finally, the authors layer heavy code obfuscation, dynamic string encryption, and anti‑emulator checks to frustrate static scanners and researchers. Dynamic cloud sandboxes like ANY.RUN, however, can still surface its behavior by executing the sample on real Android images, revealing the full attack chain.

What are the best-known SpyNote campaigns?

  • Financial Sector Focus (2022–2023): SpyNote.C began targeting banks like HSBC, Deutsche Bank, and Kotak Bank, combining spyware and banking trojan features.
  • European Surge (June–July 2023): Cleafy reported aggressive campaigns targeting European banks via phishing and smishing.
  • Cryptocurrency Theft (2024): New variants targeted crypto wallets, using Accessibility APIs to steal gestures and initiate transfers.
  • Fake Antivirus Campaigns (2024): SpyNote posed as Avast Mobile Security, using 14 domains to distribute malware.
  • Fake Google Play Pages (2025): Recent campaigns used deceptive websites mimicking Google Play to deliver SpyNote.

Gathering Threat Intelligence on SpyNote malware

ANY.RUN’s Threat Intelligence Lookup aggregates information about Android malware samples analyzed in the Interactive Sandbox. A number of SpyNote-bearing recently encountered APKs are available for investigating and collecting IOCs:

threatName:"SpyNote"

SpyNote malware samples in ANY.RUN Malicious APKs added by the Sandbox users

Each analysis session in the Sandbox contains a number of IOCs. Use them as search requests to TI Lookup for further exploring the threat and gathering data for monitoring and detection.

IOCs from SpyNote analysis Indicators of compromise from one of SpyNote samples

You can also view processes initiated by the malware to get the full picture of its operational paradigm and explore its TTPs.

SpyNote malicious processes SpyNotes activities step by step with links to TTPs

SpyNote malicious processes continued SpyNote malicious processes, continued

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SpyNote is a sophisticated Android Remote Access Trojan (RAT) that has evolved into a significant threat since its emergence around 2016. It targets Android devices, primarily to steal sensitive data, monitor user activities, and enable remote control by cybercriminals.

It is highly dangerous due to its advanced capabilities, widespread availability, and focus on financial fraud, privacy invasion, and targeted espionage. By leveraging threat intelligence, behavioral and signature-based detection, and proactive countermeasures, users and organizations can mitigate the risks posed by SpyNote.

Engage ANY.RUN’s Threat Intelligence Lookup with 50 trial requests to collect IOCs, enhance your understanding of the malware, and enforce protection.

HAVE A LOOK AT

Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More