A new and highly dangerous Android spyware, known as ClayRat, has caused concern among cybersecurity experts worldwide. It was first detected in October by the zLabs and quickly became recognized as one of the most advanced mobile threats, with the ability to take full control of infected smartphones.

A well-organized fraud operation
ClayRat mimics popular apps—like YouTube and messaging services—as well as local apps in countries like Russia (where it targets users through taxi and parking platforms). This makes it extremely dangerous, as users have little idea they are installing something malicious.
See also: SEEDSNATCHER: Android malware steals data and crypto wallets
The spyware is mainly spread via phishing sites, with more than 25 active malicious domains hosting the infected files. Additionally, cloud services such as Dropbox have been used to distribute it, dramatically increasing the reach of the campaign. Researchers have already identified over 700 unique APK files, indicating a large-scale campaign with constant variations.
Dropper technique that escapes detection
ClayRat enters the device using techniques that bypass Android's built-in security measures. It uses a sophisticated dropper mechanism, where the actual malicious payload is encrypted within the application's assets folder.
The payload is decrypted at runtime via AES/CBC, with embedded keys. The result is a highly stealthy malware that cannot be easily detected by antivirus or Google Play Protect.
During installation, it displays fake informational messages requesting SMS and accessibility permissions, exploiting users' natural trust in applications that "seem" legitimate.
See also: “Sryxen” malware manages to bypass Chrome encryption

Accessibility Services Abuse: The Secret to Persistent Stay
Once it gains access to Accessibility Services, ClayRat gains “superpowers.” It can:
- to manually bypass defenses,
- execute commands as if they were the user themselves,
- monitor and record every interaction with the device.
One of its most worrying features is that it disables the Google Play Storeby automatically performing virtual taps on the screen. This disables Play Protect, leaving the system completely exposed without the user noticing anything.
Code recording and automatic device unlocking
ClayRat records everything that happens on the lock screen — pattern swipes, PINs, passwords. This data is stored in SharedPreferences under the lock_password_storage.
The spyware then uses these elements to execute an auto_unlock, which simulates gestures and unlocks the device without any human intervention. The device thus remains accessible to attackers at all times, even if the user attempts security changes.
The level of automatic interaction suggests not just spyware, but a full remote control platform.
See also: Aisuru botnet behind 29.7 Tbps DDoS attack
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Monitoring, eavesdropping, recording: The complete package
Once installed, ClayRat can:
- takes pictures from the camera without warning,
- records the screen via MediaProjection APIs,
- recovers SMS and call logs,
- creates fake alerts to steal passwords and sensitive data.
Data collection occurs silently, without any obvious alerts or unusual activity, making it extremely difficult to detect.
A spyware that marks the next era in Android threats
ClayRat is not just another spyware; it is a sign of the ever-increasing technical sophistication of mobile threats. Its ability to install silently, bypass the user, disable critical protections, and maintain persistent access makes it one of the most serious threats of 2025.
In an environment where users are performing more and more tasks from their mobile, ClayRat reminds us how important it is to pay attention to the origin of applications and avoid installing APKs outside of confirmed sources.
