---
title: SpyNote malware now targeting banking applications
description: Discover the latest threat targeting banking applications - SpyNote malware. A new version of the spyware distributed through phishing or smishing campaigns is now specifically designed to commit banking fraud.
image: https://blog.pradeo.com/hubfs/dossier_bank.jpg
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Security Alert](https://blog.pradeo.com/topic/security-alert)

# SpyNote malware now targeting banking applications

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on October, 5 2023

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![](https://blog.pradeo.com/hubfs/dossier_bank.jpg)

###### Since June, a surge of SpyNote infections targeting banking applications has been reported. A new version of the spyware distributed through email phishing or smishing (by SMS) campaigns is now specifically designed to commit banking fraud.

SpyNote is a family of dangerous Android malware, first sold on the dark web in 2021. After the source code was leaked in 2022, multiple variants came in circulation. The latest of these variants is targeting specifically financial institutions, such as HSBC, Deutsche Bank, Kotak Bank, BurlaNubank and Bank of America.

 

## How SpyNote works  

 SpyNote is an Android spyware that abuses the accessibility services developed for people with disabilities. It detects what happens on screen and performs malicious actions accordingly. Once the application is installed and the accessibility permission is granted, the spyware uses it to accept other permissions automatically. This way, cybercriminals behind the spyware gain access to anything on the device: users’ SMS messages, call logs, contacts, GPS location, filles, photos, camera, microphone...

We recently observed that a new version of SpyNote shows advanced capabilities similar to banking malware. It is set up to perform a two-step attack, in which the second step consists in stealing banking details. To do so, it accesses the list of applications installed on users’ devices and prompts them to install a fake version of the banking application they use. It then uses keylogging and 2FA grabbing techniques to steal users’ credentials.

Nowadays, almost all banks use strong customer authentication to confirm a money transaction. But since hackers using SpyNote have full access over infected devices, they are capable of bypassing two-factor authentication. When the security code is generated by an authentication application or sent via SMS message or email, they intercept it.

SpyNote uses different defense evasion techniques, such as obfuscation, junk code and anti-emulator controls to prevent it from being launched and analyzed within an emulator or sandbox by security analysts. When the attack is successful, stolen information is monetized on the dark web and / or is used to commit banking fraud.

 

## Banks and operators of essential services directly targeted  

 Financial institutions have been the main target of SpyNote in the last few months, with banks being targeted in the United Kingdom, Germany, India and America. Additionally, hackers also focus on essential services operators. Recently, Japanese users were targeted with a SpyNote attack posing as power or water suppliers. Using vital organisations creates a sense of urgency for the victim and makes them more susceptible to act immediately.

 In addition to pirates, who obviously risk prosecution, in the future this could also be the case for companies whose apps are counterfeited. The European NIS2 directive, which goes into effect in 2024, stipulates that mobile applications and services must be protected. It recommends detecting system vulnerabilities, carrying out intrusion tests and security audits. An application that can be easily cloned and therefore used in cyberattacks could result in a penalty for the company.

 

## How to protect mobile applications  

 Now more than ever, mobile applications should never be published without prior validation of their security, especially in sectors where the data handled is sensitive.   
To assist companies, Pradeo offers a toolbox for controlling the confidentiality and security of mobile applications throughout their lifecycle, from development to operations.

 

### Take stock of current security  

 Pradeo's automated mobile application compliance audit tool enables you to:

- Obtain a compliance analysis in just a few clicks, integrating data protection laws and customizable criteria. 
- See immediately whether the application handles personal data 
- Precise detection of data manipulation by an application and its libraries, specifying whether it is used locally, sent off-device, modified or deleted. This information is completed by the location where the data is stored or sent, if applicable. 
- Identify libraries with hidden behaviors and vulnerabilities. 
- Identify risks to be remedied before an application is released. 
- Justify application security work by showing a compliant audit result. 

### Remediate vulnerabilities and protect against external attacks  

Pradeo's complementary AppSec tools enable application security managers to:

- Continuously identify and remediate application vulnerabilities right from the development stage 
- Strengthen application code to prevent theft or cloning 
- Monitor mobile applications as they are used, to detect and respond to external threats 
- Detect counterfeit applications attempting to connect to an organization's server while pretending to be legitimate 

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/hubfs/Template%20article%20(34).png)](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

###### [Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- June 30, 2026

[![2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/hubfs/Template%20article%20(31)-1.png)](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

###### [2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 \- June 11, 2026

[![Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/hubfs/Template%20article%20(30)-1.png)](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

###### [Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

 \- June 4, 2026

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 5 October, 2023

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 5 October, 2023

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 5 October, 2023

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 5 October, 2023

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 5 October, 2023

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "October 5, 2023, 8:15:00 AM",
  "datePublished" : "2023-10-05 08:15:00",
  "description" : "Discover the latest threat targeting banking applications - SpyNote malware. A new version of the spyware distributed through phishing or smishing campaigns is now specifically designed to commit banking fraud. ",
  "headline" : "SpyNote malware now targeting banking applications",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://2378615.fs1.hubspotusercontent-na1.net/hubfs/2378615/dossier_bank.jpg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```