Remote Access Trojan

SpyNote

First seen: 2016-01 • Status: active

Currently Active Threat

SpyNote is spyware for Android phones. Once installed, hackers can read your texts, listen to calls, track your location, and steal your banking apps.

Overview

SpyNote is an Android Remote Access Trojan (RAT) that gives attackers complete control over infected devices. It can steal SMS, record calls, and track location.

Also Known As

SpyNote RAT, CypherRAT

How It Spreads

  • Fake apps
  • Phishing
  • Social engineering
  • Third-party app stores

What It Does

  • Records calls and audio
  • Steals SMS messages
  • Tracks GPS location
  • Takes photos
  • Steals banking credentials

Is your business exposed?

Target Platforms

Android

Detection Tips

  • Check for apps with excessive permissions
  • Monitor battery drain

MITRE ATT&CK Techniques

T1417, T1429, T1430

If You're Infected

  1. 1.

    Factory reset the infected device

  2. 2.

    Change all passwords accessed on the device

Related Malware

Cerberus, Anubis

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required