A rapidly evolving Android spyware campaign known as the ClayRat spyware, which initially targeted Russian users but is now spreading far beyond them, has produced more than 600 samples and 50 droppers in just three months.
See also: Beware: Android Spyware Disguises as Signal and ToTok Add-on

According to observations by Zlabs , the ClayRat spyware is distributed via phishing sites and Telegram channels that pretend to be popular apps like TikTok, YouTube, and Google Photos, to trick users into installing infected APKs. In addition to secretly reading and sending text messages, taking photos, and stealing contact lists and call logs, the ClayRat spyware can spread by sending malicious links to everyone in the victim's phone's contact list, effectively turning each infection into a distribution hub.
“In many ways, mobile devices have set us back a decade,” noted John Bambenek of Bambenek Consulting. “In email, we have some protection against compromised users sending phishing bait. However, that doesn’t really exist in SMS. The result is that we artificially trust messages from our contacts, and that they may involve installing apps from sources other than Google Play.”
See also: Global Spyware Market Recognizes New Entities

By weaponizing trust from Telegram threads to SMS, the Zimperium report, shared with CSO ahead of its publication on Thursday, shows that the ClayRat spyware thrives on trust loops. Attackers use well-crafted phishing pages and “news feeds” on Telegram to host fake apps, complete with fake reviews and inflated download numbers. Once granted SMS-handling permissions, the spyware weaponizes that trust, sending messages
By exploiting the role of Android's default SMS handler, the ClayRat spyware bypasses normal execution permission checks, gaining deep access without raising any alarm to the user. Zimperium analysts found that once granted the role, ClayRat can send or intercept messages, take photos with the front-facing camera, and forward everything to its command and control (C2) servers.
See also: New Spyware Vendor Report: Targets & Infection Chains

Experts say combating ClayRat requires both technical reinforcement and behavioral hygiene. Security teams should enforce a multi-layered mobile security posture that reduces installation paths, detects breaches, and limits the blast radius.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
