Monday, November 3, 2025
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

ClayRat Spyware Targets Android Users Posing as Popular Apps

by Susan James
4 weeks ago
in News, Technology
Reading Time: 4 mins read
0
Home News
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

A new Android spyware, named ClayRat, is sweeping across Russian users by pretending to be trusted apps like WhatsApp, TikTok, Google Photos, and YouTube. Security researchers warn that this malware can steal messages, call logs, notifications, take photos, and even make calls, all while remaining hidden from the user. The campaign is rapidly expanding, with hundreds of samples discovered over the past three months.

ClayRat Campaign Tricks Users with Fake Apps

The ClayRat campaign relies on sophisticated phishing tactics to lure victims. Attackers create websites and Telegram channels that look legitimate, mimicking official service pages. These portals host or redirect users to Android package files (APKs) that contain the spyware.

To make the fake sites convincing, threat actors inflate download numbers, add fake comments, and design a Play Store-like experience. Users are guided with step-by-step instructions to sideload the APKs, bypassing Android’s built-in security warnings.

Researchers at mobile security firm Zimperium documented more than 600 ClayRat samples and 50 distinct droppers over three months, highlighting a well-organized effort to spread the spyware.

ClayRat spyware targets Android users in Russia

Hidden Installation and Session-Based Method

Some ClayRat samples act as droppers, showing a fake Play Store update screen while hiding an encrypted payload within the app. The spyware uses a session-based installation method to bypass Android 13+ restrictions, reducing suspicion.

This method increases the likelihood that a simple webpage visit will result in the spyware being installed without alerting the user. Once installed, the malware can propagate further by sending SMS messages to contacts on the infected device, effectively turning victims into distributors.

Telegram Channels Amplify the Spread

Telegram channels play a central role in ClayRat’s distribution. These channels provide links to the droppers, often framing them as updates for popular apps. Once a device is infected, the malware can automatically spread to the victim’s contacts, multiplying the attack’s reach.

This approach allows attackers to bypass traditional app stores and security controls, making the spyware harder to detect and stop.

Spyware Capabilities and Commands

ClayRat spyware is highly versatile. It can assume the default SMS handler role on infected devices, allowing it to intercept all incoming and stored messages before other apps. The malware also communicates with its command and control server (C2) using AES-GCM encryption.

ClayRat supports at least 12 commands, including:

  • get_apps_list — collects a list of installed apps

  • get_calls — sends call logs

  • get_camera — takes front-camera photos

  • get_sms_list — extracts SMS messages

  • messsms — sends mass SMS messages to contacts

  • send_sms / make_call — sends messages or places calls

  • notifications / get_push_notifications — captures notifications

  • get_device_info — gathers device details

  • get_proxy_data — sets up proxy connections

  • retransmishion — resends SMS to numbers received from C2

With granted permissions, ClayRat automatically harvests contacts and spreads itself, turning infected devices into powerful attack tools.

Industry Response and Protection

Zimperium shared ClayRat indicators of compromise with Google as part of the App Defense Alliance. Play Protect now blocks known and new variants, but experts caution that the campaign is massive and ongoing, with more than 600 samples discovered in just three months.

Experts recommend that users avoid downloading APKs from unofficial sources, scrutinize app permissions, and use security tools to detect threats. Awareness of phishing tactics, such as fake update screens, is critical in preventing infection.

Table: Key Malware Features

Feature Function Risk Level
SMS interception Reads and modifies messages High
Call logs Sends call history to C2 Medium
Camera access Takes photos secretly High
Contact harvesting Spreads malware via SMS High
Notifications Captures incoming alerts Medium

ClayRat demonstrates the growing sophistication of Android malware and highlights the risks of sideloading apps. By exploiting user trust in popular apps, attackers can infiltrate devices, steal data, and propagate infections on a large scale.

ClayRat’s rapid spread is a reminder that vigilance is essential in mobile security. Users should be cautious with app updates from unofficial sources, carefully check permissions, and monitor unusual device activity. What do you think about this new threat? Share this article with your friends to help them stay protected.

Susan James

Susan James

Susan James is a talented author and a skilled content writer. As a content writer, Susan has honed her skills in researching and understanding various topics, allowing her to produce well-rounded and engaging pieces across a wide range of subjects.

Related Posts

King Charles Prince Andrew

King Charles Strips Prince Andrew of Titles and Evicts Him Amid Epstein Scandal

4 days ago
Chipotle stock chart fall

Chipotle Stock Plunges as Weak Sales Shake Investor Confidence

4 days ago
Camila Mendes

Nicholas Galitzine Earns Praise as ‘Incredible’ He-Man in Masters of the Universe

6 days ago
biotech laboratory research

Vertex’s dominance in cystic fibrosis remains unmatched

6 days ago
Celeste claims her record labe

Celeste Alleges Record Label Threatened to Drop Her Over Album Dispute

1 week ago
Micron Technology

Micron Stock Looks Undervalued Despite Its 140% Surge in 2025

1 week ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
King Charles Prince Andrew

King Charles Strips Prince Andrew of Titles and Evicts Him Amid Epstein Scandal

October 31, 2025
Chipotle stock chart fall

Chipotle Stock Plunges as Weak Sales Shake Investor Confidence

October 31, 2025
Camila Mendes

Nicholas Galitzine Earns Praise as ‘Incredible’ He-Man in Masters of the Universe

October 28, 2025
biotech laboratory research

Vertex’s dominance in cystic fibrosis remains unmatched

October 28, 2025
Celeste claims her record labe

Celeste Alleges Record Label Threatened to Drop Her Over Album Dispute

October 25, 2025
Micron Technology

Micron Stock Looks Undervalued Despite Its 140% Surge in 2025

October 25, 2025
Chess grandmaster Daniel Naroditsky

Chess World Faces Shock After Grandmaster Naroditsky’s Death Sparks Controversy

October 24, 2025
artificial intelligence technology

Three AI Stocks Set to Dominate the Next Decade

October 24, 2025

Jennifer Aniston Reveals Her Father Tried To Stop Her From Acting

October 21, 2025
Realty Income is a real-estate investment trust

Realty Income Delivers 5.4% Yield With Strong Dividend Record

October 21, 2025

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION