Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ClayRat Android Malware Masquerades as WhatsApp & Google Photos

Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat. Over the past three months, over 600 unique samples and 50 distinct droppers have been observed.

Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat. Over the past three months, over 600 unique samples and 50 distinct droppers have been observed.

The campaign predominantly targets Russian users, employing social engineering techniques. The malware poses as popular applications such as WhatsApp, Google Photos, TikTok, and YouTube, and is distributed through deceptive Telegram channels and phishing websites.

Once installed, ClayRat is capable of extracting SMS messages, call logs, notifications, and device information. It can capture photos using the front-facing camera and send SMS messages or make calls, establishing a comprehensive surveillance system on the infected device.

Attackers set up lookalike domains to redirect users to Telegram channels where the malicious APKs are hosted. These channels employ fake social proof, such as fabricated positive comments and inflated download counts, to increase trust and facilitate installations.

Victims are often led through an installation process resembling Android's official update screens, encouraging them to enable installations from unknown sources, thereby bypassing security warnings. Phishing sites may also impersonate legitimate services to distribute the spyware.

Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat.
Jessica Grant · Thehackingpost

Zimperium's Mobile Threat Defense (MTD) and Mobile Runtime Protection (zDefend) solutions have identified ClayRat using on-device behavioral machine-learning models to detect anomalies early in the infection process.

The spyware employs advanced evasion techniques, including obfuscation and packing, and uses AES-GCM encryption for command-and-control communications. It exploits permissions in Android 13 to gain extensive SMS access without user prompts.

get_apps_list : Retrieves a list of installed applications. get_calls : Exfiltrates call logs. get_camera : Captures and uploads images from the front-facing camera. get_sms_list : Collects SMS messages. messsms : Sends mass SMS messages to all contacts. Additional commands such as send_sms and make_call .

Advertisement

As part of the App Defense Alliance, Zimperium has shared these findings with Google to ensure Google Play Protect can automatically protect users from known variants of ClayRat. Users are advised to disable installations from unknown sources, thoroughly vet applications before sideloading, and apply official updates promptly.

Enterprises should enforce mobile application management policies that restrict default SMS handler roles to trusted applications. Continuous collaboration between security vendors and platform providers is crucial to countering ClayRat's evolution and preventing widespread compromise.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories