ClayRat: A New Android Spyware Targeting Russia
ID: 6bb4e2a9-7420-5bdf-86f3-3b5364d74b45
STIX ID: report--6bb4e2a9-7420-5bdf-86f3-3b5364d74b45
Feed Name: Zimperium Blog
Zimperium researchers describe ClayRat, an actively spreading Android spyware campaign that lures victims via Telegram channels and phishing sites masquerading as popular apps; once installed it abuses the Android default SMS handler to exfiltrate SMS, call logs, notifications, device info, take front-camera photos, send SMS/calls, and auto-propagate by messaging all contacts — over 600 samples and 50 droppers were observed in three months and variants employ packing, AES-GCM, and session-based installers to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
