HomeSecurityClayRat spyware turns phones into distribution hubs

ClayRat spyware turns phones into distribution hubs

A rapidly evolving Android spyware campaign known as the ClayRat spyware, which initially targeted Russian users but is now spreading far beyond them, has produced more than 600 samples and 50 droppers in just three months.

See also: Beware: Android Spyware Disguises as Signal and ToTok Add-on

spyware ClayRat

According to observations by Zlabs , the ClayRat spyware is distributed via phishing sites and Telegram channels that pretend to be popular apps like TikTok, YouTube, and Google Photos, to trick users into installing infected APKs. In addition to secretly reading and sending text messages, taking photos, and stealing contact lists and call logs, the ClayRat spyware can spread by sending malicious links to everyone in the victim's phone's contact list, effectively turning each infection into a distribution hub.

“In many ways, mobile devices have set us back a decade,” noted John Bambenek of Bambenek Consulting. “In email, we have some protection against compromised users sending phishing bait. However, that doesn’t really exist in SMS. The result is that we artificially trust messages from our contacts, and that they may involve installing apps from sources other than Google Play.”

See also: Global Spyware Market Recognizes New Entities

ClayRat spyware turns phones into distribution hubs

By weaponizing trust from Telegram threads to SMS, the Zimperium report, shared with CSO ahead of its publication on Thursday, shows that the ClayRat spyware thrives on trust loops. Attackers use well-crafted phishing pages and “news feeds” on Telegram to host fake apps, complete with fake reviews and inflated download numbers. Once granted SMS-handling permissions, the spyware weaponizes that trust, sending messages

By exploiting the role of Android's default SMS handler, the ClayRat spyware bypasses normal execution permission checks, gaining deep access without raising any alarm to the user. Zimperium analysts found that once granted the role, ClayRat can send or intercept messages, take photos with the front-facing camera, and forward everything to its command and control (C2) servers.

See also: New Spyware Vendor Report: Targets & Infection Chains

ClayRat spyware turns phones into distribution hubs

Experts say combating ClayRat requires both technical reinforcement and behavioral hygiene. Security teams should enforce a multi-layered mobile security posture that reduces installation paths, detects breaches, and limits the blast radius.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS