SpyNote Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 4, 2025
Last Seen
July 30, 2026

SpyNote is an Android remote access Trojan (RAT) malware family that provides attackers with remote control over infected devices, enabling data exfiltration and surveillance.

Overview

SpyNote is an Android remote access Trojan (RAT) malware family that provides attackers with remote control over infected devices, enabling data exfiltration and surveillance. Recent reporting ties SpyNote to malicious Android apps on Google Play that collectively achieved about 42 million downloads, highlighting its reach within mainstream app stores and its potential for widespread impact.

Related Threat Clusters

Recent Intelligence Reports

  • Flying Eagle — hunt.io · July 30, 2026
  • Flying Eagle Android RAT source code circulates on Telegram — Feeds.Feedburner · July 30, 2026
  • Malformed Apks As An Anti Analysis Technique Malfixer Tool — www.cleafy.com · April 16, 2026
  • APK Malformation Found in Thousands of Android Malware Samples — Infosecurity-Magazine · April 16, 2026
  • Malicious Android apps on Google Play downloaded 42 million times — Bleepingcomputer · November 4, 2025

CVSS v3.1 Breakdown