216.73.217.22

Newly Registered Domains Distributing SpyNote Malware

· Published 15/04/2025 19:35 · Modified 16/04/2025 13:20

Export JSON

Essential information

Published
15/04/2025 19:35
Modified
16/04/2025 13:20
Tags
2025-04-10 2025-04-15 android androidos apk dropper data exfiltration google play store keylogging phishing rat remote access spymax spynote
Related entities
1 malware

Description

Cybercriminals are employing deceptive websites on newly registered domains to distribute malware. These sites imitate the Google Chrome install page on the , tricking users into downloading , a powerful trojan. is used for surveillance, , and remote control of infected devices. The investigation uncovered multiple domains, IP addresses, and APK files associated with this campaign. The malware utilizes various C2 endpoints for communication and , with functions designed to retrieve and manipulate device information, contacts, SMS, and applications.

External references