ClayRat Android Spyware Expands Capabilities
ID: d8d6f64c-8bb7-5854-ac24-6b998ae77786
STIX ID: report--d8d6f64c-8bb7-5854-ac24-6b998ae77786
Feed Name: Infosecurity Magazine (News)
Security researchers have identified a new, more capable iteration of the ClayRat Android spyware that combines Default SMS privileges with abusive Accessibility Services to enable keylogging (PINs, passwords, patterns), full-screen recording via MediaProjection, deceptive overlays and automated taps to prevent removal; the campaign uses over 700 distinct APKs and 25+ phishing domains (including clones of video and regional service apps) distributed via phishing sites and platforms like Dropbox, and can disable the Play Store to bypass protections, posing significant risk to BYOD environments and enterprise access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
