Threat actors are using newly registered domains to deliver the SpyNote Android remote access trojanThe SpyNote malware is delivered through spoofed app installation pages mimicking Google Play listingsOnce installed, SpyNote can record phone calls, capture keystrokes, and prevent its own uninstallationUsers and enterprise security teams are advised to remain vigilant against spoofed app pages and avoid unknown sources for APKs