SpyNote RAT
MITRE ATT&CK: S0305 View on attack.mitre.org
Aliases: SpyNote RAT
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:28:09
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps. The SpyNote RAT builder tool can be used to develop malicious apps with the malware's functionality.
Malware & tools used
- Broadcast Receivers (attack-pattern)
- Location Tracking (attack-pattern)
- Contact List (attack-pattern)
- Data from Local System (attack-pattern)
- Audio Capture (attack-pattern)
- SMS Messages (attack-pattern)
Reports & references
- MITRE ATT&CK — S0305 (report)
- zscaler.com — Spynote Rat Posing Netflix App (report)
External references
- mitre-attack — S0305
- SpyNote RAT
- Zscaler-SpyNote
- misp-galaxy
- misp-galaxy