Malware

SpyNote

Also known as: CypherRat

According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.

Indicators of Compromise 38

MITRE ATT&CK TTPs 8

Source Articles

Android malware combo takes out loans and relays victims' credit cards
A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.
bleeping-computer ·2w ago
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
The article details the discovery and analysis of a malicious Android Remote Access Tool (RAT) framework called Flying Eagle, which was leaked in early 2026 and has since been widely distributed by cybercriminal actors. The malware is distributed via fake apps impersonating Chinese government services and includes capabilities for credential theft, keylogging, screen capture, and phishing overlays. At least 170 active servers hosting the Flying Eagle infrastructure were identified, primarily in Hong Kong, using shared codebases and panel fingerprints. A new successor platform named Night Dragon has emerged, developed by the threat actor behind the @SQLRCE0 Telegram channel, indicating ongoing evolution of this mobile threat ecosystem.
static-urls