#spynote — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spynote, aggregated by home.social.
-
WindRelay Malware and SpyNote RAT Used in 13-Minute Live-Call Scam - https://www.redpacketsecurity.com/windrelay-malware-pairs-with-spynote-rat-in-live-call-scam/
-
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
Pulse ID: 6a7c6340682f0dc9b225d8d6
Pulse Link: https://otx.alienvault.com/pulse/6a7c6340682f0dc9b225d8d6
Pulse Author: AlienVault
Created: 2026-08-12 12:12:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #GroupIB #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Slovenia #SocialEngineering #SpyNote #Troll #bot #AlienVault
-
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Indicators extracted from public reporting. Source: https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
Pulse ID: 6a7c6d65bad96416b5bbfbd3
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d65bad96416b5bbfbd3
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL
-
Flying Eagle: il RAT Android che spiava per conto della «polizia cinese» finisce nelle mani sbagliate
Il codice sorgente del framework spyware Flying Eagle, dietro una finta app della polizia cinese, è trapelato su Telegram. Hunt.io mappa 170 server attivi mentre tra i criminali scoppia una guerra interna che genera già un erede, Night Dragon. -
A new #SpyNote report is out! 🚨 Dive into the tactics of this Android RAT campaign, from dynamic payload decryption to new obfuscation methods. Learn how threat actors are using deceptive Google Play Store clones to target users:
-
SpyNote Malware Targets Android Users with Fake Google Play Pages – Source: www.infosecurity-magazine.com https://ciso2ciso.com/spynote-malware-targets-android-users-with-fake-google-play-pages-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #SpyNote
-
🚨 Newly Registered Domains Distributing SpyNote Malware
The latest DomainTools Investigations (DTI) analysis reveals that deceptive websites hosted on newly registered domains are being used to deliver the potent AndroidOS SpyNote malware. These sites mimic the Google Chrome install page on the Google Play Store to lure victims into downloading SpyNote, a powerful Android remote access trojan (RAT) used for surveillance, data exfiltration, and remote control.
🔍 Key Findings:
🔷Deceptive Techniques: Websites mimic popular app installation pages to trick users.
🔷Domain Patterns: Common patterns in domain registration and website structure.
🔷Language Indicators: Mix of English and Chinese-language delivery sites.
🔷Malware Capabilities: Extensive surveillance, data theft, and remote control functionalities.SpyNote's sophisticated capabilities make it a significant threat to individuals and organizations. It can steal sensitive data, activate cameras and microphones, manipulate calls, and even remotely wipe or lock devices. The malware's persistence often requires a factory reset for complete removal.
Check out the full analysis here: https://dti.domaintools.com/newly-registered-domains-distributing-spynote-malware/?utm_source=Mastodon&utm_medium=Social&utm_campaign=SpyNote-GooglePlayStore
#SpyNote #Malware #ThreatIntelligence #CyberSecurity #InfoSec
-
SpyNote Malware Targets Android Antivirus Users – Source: www.govinfosecurity.com https://ciso2ciso.com/spynote-malware-targets-android-antivirus-users-source-www-govinfosecurity-com/ #rssfeedpostgeneratorecho #govinfosecuritycom #CyberSecurityNews #SpyNote
-
SpyNote Malware Targets Android Antivirus Users – Source: www.databreachtoday.com https://ciso2ciso.com/spynote-malware-targets-android-antivirus-users-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #SpyNote
-
Smishing campaign that downloads SpyNote to Android devices. Pretty ugly.
Why is a Command and Control server abbreviated as C2 and not CNC.. oh, nevermind. Don't google that.
-
"🔍 Dive Deep into SpyNote: The Stealthy Android Spyware 📱🕵️♂️"
SpyNote, a notorious Android spyware, has been making waves in the cybersecurity realm. This malware, primarily spread via smishing, aims to snoop on users, capturing a plethora of personal data. Some intriguing features of SpyNote include:
🔹 Stealth Mode: Once installed, it remains hidden, making it challenging for users to detect.
🔹 Diehard Services: It employs unique services that restart themselves, ensuring the malware remains active.
🔹 Phone Call Recording: SpyNote can record incoming calls, sending the recordings to its Command & Control server.
🔹 Screenshots: Using the MediaProjection API, it captures images of the user's phone screen.
🔹 Keylogging: All keystrokes are logged, capturing sensitive data like passwords.
🔹 Challenging Uninstallation: The spyware makes its removal extremely tricky, often leaving victims with the sole option of a factory reset.Stay vigilant and ensure your devices are protected against such threats. 🛡️🔒
Source: F-Secure Blog
Tags: #SpyNote #AndroidMalware #Spyware #CyberSecurity #MobileSecurity #InfoSec #ThreatAnalysis
Author: Amit Tambe
-
🚨 Malware veicolato tramite falso sito di #ITalert 🚨
ℹ️ Una campagna malevola sfrutta un domino Ad Hoc e impersona il nuovo servizio di allarme pubblico IT-Alert per veicolare il #malware #SpyNote per smartphone Android.
🔗 https://www.d3lab.net/malware-veicolato-tramite-falso-sito-di-it-alert/
-
SpyNote can also be used to bypass SMS-based two-factor authentication (2FA), which makes it even more difficult for victims to detect and prevent the attack.
-
Seit Jahren sorgt die #Android-Malware #SpyNote für Ärger. Jetzt gibt es einen sprunghaften Anstieg an Aktivitäten. https://winfuture.de/news,133890.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia