logo

SpyNote Android Spyware Poses as Legit Crypto Wallets, Steals Funds

ID: 0e4522eb-0cca-5570-9468-de734f4a3d8e

STIX ID: report--0e4522eb-0cca-5570-9468-de734f4a3d8e

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-02-16

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

FortiGuard Labs reports that the SpyNote Android Remote Access Trojan has evolved to target popular mobile cryptocurrency wallets by abusing the Accessibility API to automatically read, replace, and send crypto transfer details to attackers; malicious samples posing as legitimate wallets and distribution via smishing and fake apps have been observed, extending prior SpyNote campaigns that targeted banking apps and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.