Tuesday, October 14, 2025
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

ClayRat Spyware Targets Android Users Posing as Popular Apps

by Susan James
4 days ago
in News, Technology
Reading Time: 4 mins read
0
Home News
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

A new Android spyware, named ClayRat, is sweeping across Russian users by pretending to be trusted apps like WhatsApp, TikTok, Google Photos, and YouTube. Security researchers warn that this malware can steal messages, call logs, notifications, take photos, and even make calls, all while remaining hidden from the user. The campaign is rapidly expanding, with hundreds of samples discovered over the past three months.

ClayRat Campaign Tricks Users with Fake Apps

The ClayRat campaign relies on sophisticated phishing tactics to lure victims. Attackers create websites and Telegram channels that look legitimate, mimicking official service pages. These portals host or redirect users to Android package files (APKs) that contain the spyware.

To make the fake sites convincing, threat actors inflate download numbers, add fake comments, and design a Play Store-like experience. Users are guided with step-by-step instructions to sideload the APKs, bypassing Android’s built-in security warnings.

Researchers at mobile security firm Zimperium documented more than 600 ClayRat samples and 50 distinct droppers over three months, highlighting a well-organized effort to spread the spyware.

ClayRat spyware targets Android users in Russia

Hidden Installation and Session-Based Method

Some ClayRat samples act as droppers, showing a fake Play Store update screen while hiding an encrypted payload within the app. The spyware uses a session-based installation method to bypass Android 13+ restrictions, reducing suspicion.

This method increases the likelihood that a simple webpage visit will result in the spyware being installed without alerting the user. Once installed, the malware can propagate further by sending SMS messages to contacts on the infected device, effectively turning victims into distributors.

Telegram Channels Amplify the Spread

Telegram channels play a central role in ClayRat’s distribution. These channels provide links to the droppers, often framing them as updates for popular apps. Once a device is infected, the malware can automatically spread to the victim’s contacts, multiplying the attack’s reach.

This approach allows attackers to bypass traditional app stores and security controls, making the spyware harder to detect and stop.

Spyware Capabilities and Commands

ClayRat spyware is highly versatile. It can assume the default SMS handler role on infected devices, allowing it to intercept all incoming and stored messages before other apps. The malware also communicates with its command and control server (C2) using AES-GCM encryption.

ClayRat supports at least 12 commands, including:

  • get_apps_list — collects a list of installed apps

  • get_calls — sends call logs

  • get_camera — takes front-camera photos

  • get_sms_list — extracts SMS messages

  • messsms — sends mass SMS messages to contacts

  • send_sms / make_call — sends messages or places calls

  • notifications / get_push_notifications — captures notifications

  • get_device_info — gathers device details

  • get_proxy_data — sets up proxy connections

  • retransmishion — resends SMS to numbers received from C2

With granted permissions, ClayRat automatically harvests contacts and spreads itself, turning infected devices into powerful attack tools.

Industry Response and Protection

Zimperium shared ClayRat indicators of compromise with Google as part of the App Defense Alliance. Play Protect now blocks known and new variants, but experts caution that the campaign is massive and ongoing, with more than 600 samples discovered in just three months.

Experts recommend that users avoid downloading APKs from unofficial sources, scrutinize app permissions, and use security tools to detect threats. Awareness of phishing tactics, such as fake update screens, is critical in preventing infection.

Table: Key Malware Features

Feature Function Risk Level
SMS interception Reads and modifies messages High
Call logs Sends call history to C2 Medium
Camera access Takes photos secretly High
Contact harvesting Spreads malware via SMS High
Notifications Captures incoming alerts Medium

ClayRat demonstrates the growing sophistication of Android malware and highlights the risks of sideloading apps. By exploiting user trust in popular apps, attackers can infiltrate devices, steal data, and propagate infections on a large scale.

ClayRat’s rapid spread is a reminder that vigilance is essential in mobile security. Users should be cautious with app updates from unofficial sources, carefully check permissions, and monitor unusual device activity. What do you think about this new threat? Share this article with your friends to help them stay protected.

Susan James

Susan James

Susan James is a talented author and a skilled content writer. As a content writer, Susan has honed her skills in researching and understanding various topics, allowing her to produce well-rounded and engaging pieces across a wide range of subjects.

Related Posts

Explore five stocks that surged over 1,000 percent in 2025

Five Stocks That Skyrocketed Over 1,000 Percent This Year

18 hours ago
Al Pacino and Diane Keaton

Al Pacino Regrets Never Marrying Diane Keaton After Her Death

18 hours ago
JPMorgan CEO Jamie Dimon

JPMorgan Chief Warns US Stock Crash Risk Could Hit Soon

4 days ago
Bitcoin remains the top cryptocurrency

Bitcoin Remains the Clear Choice for Smart Crypto Investors

4 days ago
ExxonMobil and Enterprise Products

Top Energy Stocks Offering High Dividends for Reliable Income

1 week ago
Windows 11 desktop

Start11 Update Brings Major Fixes and New Features for Windows 11

2 weeks ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
Explore five stocks that surged over 1,000 percent in 2025

Five Stocks That Skyrocketed Over 1,000 Percent This Year

October 13, 2025
Al Pacino and Diane Keaton

Al Pacino Regrets Never Marrying Diane Keaton After Her Death

October 13, 2025
JPMorgan CEO Jamie Dimon

JPMorgan Chief Warns US Stock Crash Risk Could Hit Soon

October 10, 2025
ClayRat spyware targets Android users in Russia

ClayRat Spyware Targets Android Users Posing as Popular Apps

October 10, 2025
Bitcoin remains the top cryptocurrency

Bitcoin Remains the Clear Choice for Smart Crypto Investors

October 10, 2025
staying hydrated in winter

Why Staying Hydrated in Winter Is Just as Important as in Summer

October 9, 2025
ExxonMobil and Enterprise Products

Top Energy Stocks Offering High Dividends for Reliable Income

October 6, 2025
Windows 11 desktop

Start11 Update Brings Major Fixes and New Features for Windows 11

October 3, 2025
AstraZeneca

AstraZeneca Shares Surge After Pfizer U.S. Deal Sparks Optimism

October 3, 2025
Nichole

Nicole Kidman Files for Divorce From Keith Urban After 19 Years

October 1, 2025

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION