Drooid Logo
Back to story perspectives

Full Breakdown

ClayRat Spyware Campaign Targets Android Users in Russia

10/10/2025, 11:29:39 AM

Overview of the ClayRat Spyware Campaign

The ClayRat spyware campaign has emerged as a significant threat primarily targeting Android users in Russia. This rapidly evolving malware utilizes a combination of Telegram channels and phishing websites that impersonate popular applications such as WhatsApp, TikTok, Google Photos, and YouTube to deceive users into downloading malicious software. Over the past three months, researchers from Zimperium's zLabs have identified more than 600 distinct samples and 50 droppers of ClayRat, each iteration incorporating advanced obfuscation techniques to evade detection.

Distribution Tactics and Mechanisms

ClayRat's distribution strategy relies heavily on social engineering and web deception. Attackers create convincing phishing sites that mimic legitimate services, often redirecting users to Telegram channels where malicious APK files are hosted. These channels frequently feature fake testimonials and inflated download counts to build credibility. Once installed, ClayRat exploits Android's default SMS handler role, allowing it to gain extensive permissions without triggering standard security prompts. This capability enables the malware to read, send, and intercept SMS messages, as well as to exfiltrate sensitive data such as call logs and notifications.

Surveillance Capabilities

Once activated, ClayRat can perform a range of invasive actions, including taking photos with the device's front camera, sending SMS messages, and placing calls directly from the victim's device. The malware can also disseminate itself by sending malicious links to every contact in the victim's phone book, effectively turning each infected device into a distribution hub. This self-propagation mechanism significantly amplifies the malware's reach, allowing it to spread rapidly among users.

Official Statements & Responses

In response to the threat posed by ClayRat, a Google spokesperson stated that Android users are automatically protected against known versions of the malware through Google Play Protect, which is enabled by default on devices with Google Play Services. Zimperium has shared its findings with Google to enhance protective measures against this spyware.

Criticism & Opposition

Experts have raised concerns about the implications of ClayRat's tactics. John Bambenek, President of Bambenek Consulting, emphasized the importance of only installing applications from authorized app stores, warning that the malware's ability to send authentic-looking messages could facilitate sophisticated impersonation attacks. Additionally, Jason Soroko from Sectigo highlighted the need for organizations to adopt a layered mobile security posture to mitigate risks associated with such malware.

What's Next

As the ClayRat campaign continues to evolve, cybersecurity experts recommend that users remain vigilant and avoid installing applications from untrusted sources. Organizations are encouraged to educate employees about the dangers of social engineering and to implement strict policies regarding app installations. The rapid proliferation of ClayRat underscores the urgent need for enhanced security measures in the mobile threat landscape.

Verbatim Quotes

  • “ClayRat is a new Android spyware that hides inside fake apps that mimic popular apps such as TikTok, YouTube or Google Photos, and tricks users into giving it special permissions,” — Chrissa Constantine, Senior Cybersecurity Solution Architect at Black Duck
  • “The sheer scale of this campaign—over 600 observed samples in just three months—highlights how quickly the mobile threat landscape is changing.” — Zimperium Report
  • “The key protection for any mobile device user is to only install applications from authorized Play/App stores, even if they get a message from an otherwise familiar contact.” — John Bambenek, President at Bambenek Consulting
  • “ClayRat poses a serious threat not only because of its extensive surveillance capabilities, but also because of its abuse of Android’s default SMS handler role.” — Zimperium Report