SpyNote RAT - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:37:59 UTC Tool: SpyNote RAT Names SpyNote RAT SpyNote CypherRat Category Malware Type Backdoor, Info stealer, Exfiltration Description SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps. The SpyNote RAT builder tool can be used to develop malicious apps with the malware's functionality. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 26 December 2024 Download this tool card in JSON format All groups using tool SpyNote RAT Changed Name Country Observed https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f6df192b-ad71-4097-b372-0edf8a586d50 Page 1 of 2 APT groups   OilAlpha 2022     OilRig, APT 34, Helix Kitten, Chrysene 2014-Sep 2024   Syrian Electronic Army (SEA), Deadeye Jackal 2011-Aug 2021       ↳ Subgroup: Pat Bear, APT-C-37 2015   4 groups listed (4 APT, 0 other, 0 unknown) ↑ Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f6df192b-ad71-4097-b372-0edf8a586d50 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f6df192b-ad71-4097-b372-0edf8a586d50 Page 2 of 2