Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users

## Cybersecurity: New Android Malware Threat - ClayRat

Cybersecurity: New Android Malware Threat - ClayRat

A newly identified Android spyware, known as ClayRat, poses a significant threat in 2025. It disguises itself as popular applications such as WhatsApp, Google Photos, TikTok, and YouTube to gain unauthorized access to devices and extract sensitive data.

ClayRat is a comprehensive surveillance tool designed to extract SMS messages, call logs, device notifications, and personal information. It can covertly access infected devices and capture images using the front-facing camera. Additionally, it can send malicious links to contacts, turning each infected device into a distribution point for further infections.

Over recent months, over 600 malware samples and 50 dropper variants have been documented. Each iteration incorporates new obfuscation and packing techniques to evade detection systems. The malware's distribution network primarily uses Telegram channels and phishing websites that mimic legitimate service pages to distribute malicious APK files.

A newly identified Android spyware, known as ClayRat, poses a significant threat in 2025.
Brian Shaw · Thehackingpost

ClayRat establishes persistent access by exploiting Android's SMS handler role, allowing it to manage messaging functions without user detection. It employs session-based installation methods to bypass Android 13 security restrictions. Fake Google Play Store update screens are used to trick users into installing the malware.

Once installed and granted SMS handler privileges, ClayRat begins surveillance operations. It can execute remote commands such as application enumeration, call log exfiltration, and unauthorized SMS transmission. Communication with command-and-control servers is conducted through standard HTTP protocols with obfuscation techniques like Base64 encoding and AES-GCM encryption.

Advertisement

The malware's self-propagation mechanism allows it to send malicious links to all contacts in the victim's phonebook, exploiting social trust relationships to rapidly expand the campaign.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories