Spymax Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 9, 2025
Last Seen
December 16, 2025

Spymax is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 9, 2025; most recent activity December 16, 2025.

Overview

Spymax is an Android-focused malware family used to facilitate surveillance and remote control of infected devices, enabling financially motivated fraud operations. Recent reporting ties Spymax to a syndicate whose members created malware tutorials to teach others how to run scams, resulting in significant financial losses and law enforcement action, underscoring its impact on malware-enabled financial crime.

Related Threat Clusters

  • Singapore Man Jailed for Teaching Malware Use

    Cheoh Hai Beng, a 49-year-old Malaysian national, was sentenced to five and a half years in prison in Singapore for creating and distributing approximately 20 video tutorials on how to use malware to infect Android…

    1 article · Updated December 16, 2025
  • Malaysian Man Jailed for Creating Malware Scam Tutorials

    Cheoh Hai Beng, a 49-year-old Malaysian, was sentenced for producing at least 20 videos instructing others on how to use malware to scam Singaporeans. The criminal syndicate he was part of resulted in 129 victims losing…

    3 articles · Updated December 9, 2025

Recent Intelligence Reports

  • Singapore jails man for teaching malware use — Scworld · December 16, 2025
  • Jail for man who made videos to show viewers how run scams using malware — Straitstimes · December 9, 2025
  • Man gets jail for filming malware tutorials for syndicate; 129 Singapore victims lost S$3.2m — Channelnewsasia · December 9, 2025

CVSS v3.1 Breakdown