SpyNote is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity April 16, 2026.
SpyNote is an Android remote access Trojan (RAT) malware family that provides attackers with remote control over infected devices, enabling data exfiltration and surveillance. Recent reporting ties SpyNote to malicious Android apps on Google Play that collectively achieved about 42 million downloads, highlighting its reach within mainstream app stores and its potential for widespread impact.
APK malformation has become a prevalent anti-analysis technique in Android malware, identified in over 3,000 samples from various families, including Teabot, TrickMo, Godfather, and SpyNote. Attackers exploit the…
A report from Zscaler indicates a 67% increase in malware targeting Android devices from June 2024 to May 2025. During this period, 239 malicious apps bypassed Google Play's security filters and were downloaded over 42…
Over 42 million downloads of malicious Android apps were reported in India, making it the largest target for mobile malware. The Zscaler ThreatLabz 2025 report noted a 67% increase in malware targeting Android devices…