Malware
SpyNote
Also known as: CypherRat
According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.
Indicators of Compromise 38
Domain 110gongan[.]com Domain alcs[.]xyttkx[.]cc Domain fusu[.]us[.]ci Domain h5[.]xyttkx[.]cc Domain ls[.]j2x8a[.]top Domain s[.]orove[.]cn Domain txl[.]xyttkx[.]cc Filename ApkBuilder.php Filename Eaod29251.php Filename Eaod85401.php Filename EaodWorker.exe Filename SECRIT_KEY Filename SpyNote.apk Filename WindRelay.apk GitHub Repo 中国龙.zip GitHub Repo 飞鹰控打包.zip SHA-256 0376db397807c1f1e32a99a9db622f35f4fe5597bd05b4fd5e93117062e0131f SHA-256 1456f31bf6b5d4ade90fe080006478133296080353bf69c1819fa9b766e7f57a SHA-256 4395db6ad53a415532673b16f5b64207d53cecc5b15a736c038cf3890368a164 SHA-256 5dee5cde6f2874c582effe302960b21569ee007e9e0cd4f7499d418cceb9095b SHA-256 773c77494d6321e4e449c9558c7915166bcb6c05e3c42a9d30e5eac4db8ee0df SHA-256 82520e6aa6194b2de0b1c404805a5da7d3693acab8f7ae2dd5104f14baf82cd7 SHA-256 b803cd5032dc1abd7aabc45c8cadc471c8a59872a95d48807f13e230c58230f3 SHA-256 c692ad120cc90548d48dbe57d006f2403c49833b8993af3c38fe031eb39999bd SHA-256 d8a82d7b4457352774772bfac094127d7f67526ae7011d838cc3f7ccc15fd86e SHA-512 7fe8d14e7a9cda92c79d5ae836ed95d772bcc853079c4020c5213c3894c7f7af IP 108[.]187[.]7[.]66 IP 108[.]187[.]7[.]71 IP 154[.]44[.]25[.]12 IP 207[.]56[.]30[.]188 IP 207[.]56[.]30[.]194 IP 77[.]105[.]161[.]235 IP 85[.]137[.]253[.]48 IP 91[.]108[.]20[.]15 IP 91[.]108[.]20[.]16 IP 91[.]108[.]20[.]17 IP 91[.]108[.]20[.]18 Package com.icontrol.protector
MITRE ATT&CK TTPs 8
T1056 T1059.001 T1071.001 T1095 T1105 T1132.001 T1219 T1482
Input Capture
Collection
PowerShell
Execution
Web Protocols
Command And Control
Non-Application Layer Protocol
Command And Control
Ingress Tool Transfer
Command And Control
Standard Encoding
Command And Control
Remote Access Software
Command And Control
Domain Trust Discovery
Discovery
Source Articles
Android malware combo takes out loans and relays victims' credit cards
A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.
bleeping-computer ·2w ago
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
The article details the discovery and analysis of a malicious Android Remote Access Tool (RAT) framework called Flying Eagle, which was leaked in early 2026 and has since been widely distributed by cybercriminal actors. The malware is distributed via fake apps impersonating Chinese government services and includes capabilities for credential theft, keylogging, screen capture, and phishing overlays. At least 170 active servers hosting the Flying Eagle infrastructure were identified, primarily in Hong Kong, using shared codebases and panel fingerprints. A new successor platform named Night Dragon has emerged, developed by the threat actor behind the @SQLRCE0 Telegram channel, indicating ongoing evolution of this mobile threat ecosystem.
static-urls