Threats Tagged 'clayrat'
View all threats tagged with 'clayrat'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'clayrat'
Click on any threat for detailed analysis and mitigation recommendations
ClayRat is an Android spyware campaign primarily targeting Russian users by masquerading as popular apps distributed through Telegram channels and phishing sites. It exfiltrates SMS, call logs, notifications, device info, takes photos, and sends SMS messages. The malware spreads aggressively by sending malicious links to victims' contacts, leveraging Android's default SMS handler role to bypass permission prompts. Over 600 samples and 50 droppers have been observed in three months, with continuous obfuscation improvements. The campaign uses impersonation, community distribution, UX deception, and self-propagation via SMS forwarding. While currently focused on Russia, the techniques and propagation methods pose risks to European organizations with Android users. No known exploits are publicly reported, and the campaign requires user interaction to install and propagate. Suggested severity is medium due to its impact on confidentiality and propagation capabilities but limited to targeted regions and requiring user action. Join the discussion | AlienVault OTX General | 10/10/2025, 08:17:49 UTC Added: 10/10/2025, 08:36:17 UTC |
Showing 1 to 1 of 1 result