ClayRat Android Malware Masquerades as WhatsApp & Google Photos
Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat. Over the past three months, over 600 unique samples and 50 distinct droppers have been observed.
Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat. Over the past three months, over 600 unique samples and 50 distinct droppers have been observed.
The campaign predominantly targets Russian users, employing social engineering techniques. The malware poses as popular applications such as WhatsApp, Google Photos, TikTok, and YouTube, and is distributed through deceptive Telegram channels and phishing websites.
Once installed, ClayRat is capable of extracting SMS messages, call logs, notifications, and device information. It can capture photos using the front-facing camera and send SMS messages or make calls, establishing a comprehensive surveillance system on the infected device.
Attackers set up lookalike domains to redirect users to Telegram channels where the malicious APKs are hosted. These channels employ fake social proof, such as fabricated positive comments and inflated download counts, to increase trust and facilitate installations.
Victims are often led through an installation process resembling Android's official update screens, encouraging them to enable installations from unknown sources, thereby bypassing security warnings. Phishing sites may also impersonate legitimate services to distribute the spyware.
Recent analysis has identified a significant increase in activity from the Android spyware campaign known as ClayRat.
Zimperium's Mobile Threat Defense (MTD) and Mobile Runtime Protection (zDefend) solutions have identified ClayRat using on-device behavioral machine-learning models to detect anomalies early in the infection process.
The spyware employs advanced evasion techniques, including obfuscation and packing, and uses AES-GCM encryption for command-and-control communications. It exploits permissions in Android 13 to gain extensive SMS access without user prompts.
get_apps_list : Retrieves a list of installed applications. get_calls : Exfiltrates call logs. get_camera : Captures and uploads images from the front-facing camera. get_sms_list : Collects SMS messages. messsms : Sends mass SMS messages to all contacts. Additional commands such as send_sms and make_call .
As part of the App Defense Alliance, Zimperium has shared these findings with Google to ensure Google Play Protect can automatically protect users from known variants of ClayRat. Users are advised to disable installations from unknown sources, thoroughly vet applications before sideloading, and apply official updates promptly.
Enterprises should enforce mobile application management policies that restrict default SMS handler roles to trusted applications. Continuous collaboration between security vendors and platform providers is crucial to countering ClayRat's evolution and preventing widespread compromise.
Based on reporting by GBHackers.
