logo

Russia-linked malware operation collapses after security failures, developer’s arrest

ID: a0ca0381-7d45-523e-851b-a379165e8d4d

STIX ID: report--a0ca0381-7d45-523e-851b-a379165e8d4d

Feed Name: The Record from Recorded Future News

Threat Score
55/100

Date Published: 2026-03-23

Date Updated: 2026-05-01

...
...

Researchers observed ClayRat, an Android remote-access spyware campaign that spread via phishing sites and fake apps and was marketed via Telegram subscriptions; it produced over 600 samples but quickly deteriorated and went offline after technical weaknesses and the suspected developer’s arrest.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.