Check out the results from our first round of ATT&CK Evaluations at attackevals.mitre.org!

SpyNote RAT

SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps. The SpyNote RAT builder tool can be used to develop malicious apps with the malware's functionality. [1]

ID: S0305
Aliases: SpyNote RAT
Type: MALWARE
Platforms: Android

Version: 1.1

Alias Descriptions

NameDescription
SpyNote RAT[1]

Techniques Used

DomainIDNameUse
MobileT1432Access Contact ListSpyNote RAT can view contacts.[1]
MobileT1409Access Sensitive Data or Credentials in FilesSpyNote RAT can copy files from the device to the C2 server.[1]
MobileT1402App Auto-Start at Device BootSpyNote RAT uses an Android broadcast receiver to automatically start when the device boots.[1]
MobileT1412Capture SMS MessagesSpyNote RAT can read SMS messages.[1]
MobileT1430Location TrackingSpyNote RAT collects the device's location.[1]
MobileT1429Microphone or Camera RecordingsSpyNote RAT can activate the victim's microphone.[1]

References