SpyNote RAT posing as Netflix app
ID: acd37017-6b76-5d0f-8c39-e966fa6ac849
STIX ID: report--acd37017-6b76-5d0f-8c39-e966fa6ac849
Feed Name: Zscaler Security Research Blog
This Zscaler analysis describes a fake Netflix Android app that is an updated variant of the SpyNote RAT. The malware provides full remote-access and spying capabilities (audio recording, screen capture via MediaProjection, command execution, file exfiltration, SMS and contact theft, camera control and uninstalling of apps), uses Android services and broadcast receivers for persistence, contacts C&C via free DNS, and is designed to operate over Wi-Fi. The report warns that the SpyNote builder is widely used—120+ variants were observed in the first two weeks of 2017—and includes sample hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
