SpyNote Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 4, 2025
Last Seen
April 16, 2026

SpyNote is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity April 16, 2026.

Overview

SpyNote is an Android remote access Trojan (RAT) malware family that provides attackers with remote control over infected devices, enabling data exfiltration and surveillance. Recent reporting ties SpyNote to malicious Android apps on Google Play that collectively achieved about 42 million downloads, highlighting its reach within mainstream app stores and its potential for widespread impact.

Related Threat Clusters

Recent Intelligence Reports

  • Malformed Apks As An Anti Analysis Technique Malfixer Tool — www.cleafy.com · April 16, 2026
  • APK Malformation Found in Thousands of Android Malware Samples — Infosecurity-Magazine · April 16, 2026
  • Malicious Android apps on Google Play downloaded 42 million times — Bleepingcomputer · November 4, 2025

CVSS v3.1 Breakdown