ClayRat Spyware Targets Russian Android Users via Telegram

09 Oct 2025

ClayRat, a rapidly evolving Android spyware campaign, is targeting users in Russia using Telegram channels and phishing websites. The spyware mimics popular apps like WhatsApp and YouTube to trick users into installation.

Spyware Functionality

Once activated, ClayRat spyware can exfiltrate sensitive data such as SMS messages, call logs, and device information. It can also take photos using the device's front camera, send SMS messages, and make calls. According to Zimperium researcher Vishnu Pratapagiri, the malware spreads by sending malicious links to every contact in the victim's phone book.

  • Targets: Russian Android users.
  • Platforms: Phishing sites mimic popular apps.
  • Distribution: Telegram channels and malicious links.
  • Data Stolen: SMS, calls, notifications, and device info.

Technical Mechanics

Zimperium has identified at least 600 samples and 50 droppers over the last 90 days. The spyware's evolving iterations are using obfuscation methods to evade detection. ClayRat utilizes a command-and-control (C2) panel for administration, redirecting users to fraudulent sites that inflate download counts with fabricated testimonials.

Some samples act as droppers, creating a faux Play Store update while concealing the real payload in the app's assets. The malware exploits standard HTTP communication with its C2 and requests permissions to be the default SMS app to secretly capture and disseminate messages.

Implications and Broader Risks

The campaign underscores broader mobile security concerns, as demonstrated by a separate study on budget Android phones sold in Africa. Conducted by the University of Luxembourg and Université Cheikh Anta Diop, the study revealed that preinstalled apps often possess elevated privileges, leading to risks like data disclosure and unauthorized actions.

This highlights the need for increased vigilance and better security measures for Android devices worldwide.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6365223
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1262323
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
494861
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453313
downloads

News and reviews for Mobile Android

Game 'Green Light' Coming to PC, iOS, and Android by 2026

Dream Adventure Game 'Green Light' announced for PC, iOS, Android, 2026. Experience yanaginagi's world. Launch expected with English, Japanese support.

Read more

Free Apps Now Available for Android and iOS Users

Enjoy free premium apps on Android and iOS. Limited-time offer. Download now for lasting access.

Read more

AppHub Uninstalled from T-Mobile Devices for Improved Privacy

T-Mobile removes AppHub from Android devices amid privacy concerns over silent app installations.

Read more

LibriVox Makes Audiobooks Free for Android Auto Users

LibriVox offers over 18,000 free audiobooks for Android Auto users, enhancing long drives with public-domain classics and seamless in-car integration.

Read more

Unveil Huge Android App Discounts This Week

Discover significant app discounts on Android, including game and utility deals, available this week.

Read more

Latest Android Deals Include Trudograd Price Drop

Android deals now offer discounts on apps like Trudograd and Boxville 2, enhancing affordability for tech enthusiasts.

Read more

Top Free Apps to Enhance Your New Android Experience

Explore five free apps for Android that boost privacy, browsing, and productivity, offering solid performance with no cost.

Read more

Google Adds AI Summaries to Play Store Reviews

Google introduces AI-generated review summaries on Play Store, aiding app selection by highlighting key pros and cons under user reviews.

Read more

FBI Urges Changes to Encryption in Messaging Apps

FBI pushes for decryption in U.S. messaging apps to tackle crime. Impact on privacy debated.

Read more

SlopAds Ad-Fraud Uncovered in 224 Android Apps

SlopAds ad-fraud scheme impacts 224 Android apps on Google Play, affecting over 38 million downloads. Google removes apps; users should deploy Play Protect.

Read more