New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users
## Cybersecurity: New Android Malware Threat - ClayRat
Cybersecurity: New Android Malware Threat - ClayRat
A newly identified Android spyware, known as ClayRat, poses a significant threat in 2025. It disguises itself as popular applications such as WhatsApp, Google Photos, TikTok, and YouTube to gain unauthorized access to devices and extract sensitive data.
ClayRat is a comprehensive surveillance tool designed to extract SMS messages, call logs, device notifications, and personal information. It can covertly access infected devices and capture images using the front-facing camera. Additionally, it can send malicious links to contacts, turning each infected device into a distribution point for further infections.
Over recent months, over 600 malware samples and 50 dropper variants have been documented. Each iteration incorporates new obfuscation and packing techniques to evade detection systems. The malware's distribution network primarily uses Telegram channels and phishing websites that mimic legitimate service pages to distribute malicious APK files.
A newly identified Android spyware, known as ClayRat, poses a significant threat in 2025.
ClayRat establishes persistent access by exploiting Android's SMS handler role, allowing it to manage messaging functions without user detection. It employs session-based installation methods to bypass Android 13 security restrictions. Fake Google Play Store update screens are used to trick users into installing the malware.
Once installed and granted SMS handler privileges, ClayRat begins surveillance operations. It can execute remote commands such as application enumeration, call log exfiltration, and unauthorized SMS transmission. Communication with command-and-control servers is conducted through standard HTTP protocols with obfuscation techniques like Base64 encoding and AES-GCM encryption.
The malware's self-propagation mechanism allows it to send malicious links to all contacts in the victim's phonebook, exploiting social trust relationships to rapidly expand the campaign.
Based on reporting by Cyber Security News.
