• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

Over 600 ClayRat Spyware Variants Spread via Telegram and Phishing Sites

Published on: October 10, 2025
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 391 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Flipper One Brings AI and Linux to a Pocket Sized Device
New Megalodon Malware Hits Thousands of GitHub Projects
Microsoft Patches Active Defender Zero Day Vulnerabilities
Android Clayrat Malware Spread Through Telegram Channels
As Featured In
BluehostActive CampaignDesignrushSeeking AlphaResearch Com
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A fast-spreading Android spyware campaign named ClayRat is targeting Russian users through fake Telegram channels and phishing sites imitating popular apps like WhatsApp and YouTube.

Quick Summary – TLDR:

  • ClayRat is Android spyware targeting Russian users via fake Telegram channels and phishing websites
  • The malware impersonates apps like WhatsApp, TikTok, YouTube, and Google Photos
  • Over 600 malware samples and 50 unique droppers were discovered in just three months
  • ClayRat spreads by hijacking SMS permissions and turning infected phones into distribution hubs

What Happened?

Researchers at mobile security firm Zimperium uncovered a large-scale Android spyware campaign called ClayRat. The spyware uses a combination of Telegram channels, phishing websites, and fake APKs to trick users into downloading malware disguised as popular apps. Once installed, it abuses Android’s SMS handling permissions to spread further, capturing sensitive data and turning devices into part of its distribution chain.

THREAT ALERT 🚨

Our #zLabs team has been tracking ClayRat, a rapidly spreading Android spyware posing as popular apps.

Zimperium MTD and zDefend deliver protection against ClayRat and its variants.

Learn more: https://t.co/xcu5e5rJ58 pic.twitter.com/Xf9WoRN5Sv

— Zimperium (@Zimperium) October 9, 2025

ClayRat Malware Disguises as Popular Apps

The ClayRat spyware campaign is focused on deceiving users with convincing phishing sites and Telegram-hosted APK files that look like legitimate services such as WhatsApp, TikTok, Google Photos, and YouTube. These fake portals feature inflated download counts, fake user reviews, and even Play Store-like UX, complete with detailed sideloading instructions to bypass Android’s built-in warnings.

The malware samples have been evolving rapidly. Over 600 variants and 50 different droppers were found within just three months, each version adding new layers of obfuscation and encryption to avoid detection.

Abuses SMS Permissions for Stealth and Spread

Once installed, ClayRat requests to become the device’s default SMS handler, granting it the ability to:

  • Read, send, and intercept SMS messages
  • Modify SMS databases
  • Harvest contact lists
  • Silently send messages to all contacts

By sending socially engineered SMS messages (such as “Узнай первым! <link>”) to a victim’s entire contact list, each compromised device becomes a malware distribution node. This exponential spread means attackers can rapidly infect new users without needing to build new infrastructure.

Zimperium’s researchers noted, “Because these messages appear to come from a trusted source, recipients are far more likely to click the link, join the same Telegram channel, or visit the same phishing site.”

Newsletter
Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Powerful Spyware Capabilities

ClayRat’s newer variants use AES-GCM encryption for C2 (command-and-control) communication and support at least 12 different commands that enable extensive surveillance and control:

  • Take photos using the front camera
  • Send call logs and SMS to the server
  • Place calls and send SMS remotely
  • Capture notifications and device info
  • Harvest installed app lists
  • Use WebSocket proxy data for stealthy communications

Some samples even show fake update screens while silently decrypting and loading malicious payloads in the background.

Zimperium Flags the Threat, Google Responds

Zimperium, a member of the App Defense Alliance, shared indicators of compromise (IoCs) with Google. As a result, Google Play Protect now detects and blocks known ClayRat variants. However, the scale and sophistication of the campaign suggest it’s far from over.

SQ Magazine’s Takeaway

I think this ClayRat campaign is one of the more dangerous spyware efforts we’ve seen in recent months. Not just because it steals personal data, but because it turns your own phone into a trap for your friends and family. That’s what really sets it apart. It abuses the trust people place in their contacts to spread silently and fast. If you’re sideloading APKs or joining Telegram channels for unofficial app downloads, stop now. The stakes have changed.

SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

FBI Warns Iran Using Telegram to Spy on Dissidents Worldwide
Cybersecurity

FBI Warns Iran Using Telegram to Spy on Dissidents Worldwide

ChatGPT Misused for Surveillance and Phishing: OpenAI Cracks Down
Artificial Intelligence

ChatGPT Misused for Surveillance and Phishing: OpenAI Cracks Down

Cybercriminals Exploit TinyLoader Malware to Hijack Crypto and Infiltrate Networks
Cybersecurity

Cybercriminals Exploit TinyLoader Malware to Hijack Crypto and Infiltrate Networks

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

108 Chrome Extensions Found Stealing Customers Data
Signal and WhatsApp Users Targeted by Russian Hackers
131 Chrome Extensions Busted for WhatsApp Web Spam Scheme

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • ClayRat Malware Disguises as Popular Apps
  • Abuses SMS Permissions for Stealth and Spread
  • Powerful Spyware Capabilities
  • Zimperium Flags the Threat, Google Responds
  • SQ Magazine’s Takeaway
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Reddit Statistics
  • Spotify User Statistics
  • TikTok vs. Instagram Statistics
  • Gen Z Social Media Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
TikTok Brain Statistics 2026: Attention, Memory, Health
TikTok Brain Statistics 2026: Attention, Memory, Health
TikTok Music Statistics 2026: Discovery, Charts and Streaming
TikTok Music Statistics 2026: Discovery, Charts and Streaming
Generation Alpha Statistics 2026: Population, Screen Time and Spending Power
Generation Alpha Statistics 2026: Population, Screen Time and Spending Power
Fake News Statistics 2026: Spread, Trust and AI Content Farms
Fake News Statistics 2026: Spread, Trust and AI Content Farms
Social Media Addiction Statistics 2026: Prevalence and Mental Health Data
Social Media Addiction Statistics 2026: Prevalence and Mental Health Data
Gaming
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Video Games Industry Statistics 2026: Big Insights
Video Games Industry Statistics 2026: Big Insights
Game Streaming Statistics 2026: Powerful Trends
Game Streaming Statistics 2026: Powerful Trends
In-Game Purchases Statistics 2026: Market Secrets
In-Game Purchases Statistics 2026: Market Secrets
Xbox Statistics 2026: Surging Player Growth
Xbox Statistics 2026: Surging Player Growth
Nintendo Statistics 2026: Explosive Trends Now
Nintendo Statistics 2026: Explosive Trends Now
Technology
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
iPhone Ecosystem Statistics 2026: Big Market Trends
iPhone Ecosystem Statistics 2026: Big Market Trends
Average Screen Time by Age Statistics 2026: Latest Insights
Average Screen Time by Age Statistics 2026: Latest Insights
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Voice Search Statistics 2026: Adoption, Devices & SEO Data
Voice Search Statistics 2026: Adoption, Devices & SEO Data
Artificial Intelligence
AI Influencer Marketing Statistics: Market Size and Engagement
AI Influencer Marketing Statistics: Market Size and Engagement
AI Market Statistics 2026: Size, Growth & Investment
AI Market Statistics 2026: Size, Growth & Investment
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
AI Overviews Statistics 2026: Google Search Impact Data
AI Overviews Statistics 2026: Google Search Impact Data
AI Recruitment Statistics 2026: Hiring Trends & Data
AI Recruitment Statistics 2026: Hiring Trends & Data
Cybersecurity
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics 2026: Key Fraud Data and Trends
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics 2026: Hidden Threats
API Security Breach Statistics 2026: Hidden Threats
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Discord Rolls Out End-to-End Encrypted Calls for All Users
Discord Rolls Out End-to-End Encrypted Calls for All Users
Netflix Accused of Secret User Tracking in Major Texas Lawsuit
Netflix Accused of Secret User Tracking in Major Texas Lawsuit
Spotify Confirms Major App Outage and Streaming Issues
Spotify Confirms Major App Outage and Streaming Issues
Meta Starts Rolling Out WhatsApp Plus Subscription on iOS
Meta Starts Rolling Out WhatsApp Plus Subscription on iOS
Prime Video Launches Vertical Clips Feed for Movies and Shows
Prime Video Launches Vertical Clips Feed for Movies and Shows
Microsoft Xbox Overhaul Begins as Copilot Gets Cut
Microsoft Xbox Overhaul Begins as Copilot Gets Cut
Gaming
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
New Dissidia Final Fantasy Mobile Game Incoming for iOS and Android
New Dissidia Final Fantasy Mobile Game Incoming for iOS and Android
Technology
Flipper One Brings AI and Linux to a Pocket Sized Device
Flipper One Brings AI and Linux to a Pocket Sized Device
Apple Brings Sleep Apnoea Alerts and Hearing Test to India
Apple Brings Sleep Apnoea Alerts and Hearing Test to India
Googlebook Announced With Gemini AI and Premium Design
Googlebook Announced With Gemini AI and Premium Design
Apple and Intel Reach Preliminary Chip Manufacturing Deal
Apple and Intel Reach Preliminary Chip Manufacturing Deal
OpenAI Drops Robotics and Hardware Spinout Plan Before IPO
OpenAI Drops Robotics and Hardware Spinout Plan Before IPO
watchOS 27 Leak Shows New Modular Watch Face Design
watchOS 27 Leak Shows New Modular Watch Face Design
Artificial Intelligence
OpenAI and 1Password Team Up to Secure AI Coding Agent Codex
OpenAI and 1Password Team Up to Secure AI Coding Agent Codex
Alibaba Bets Big on AI Agents With New Zhenwu M890 Processor
Alibaba Bets Big on AI Agents With New Zhenwu M890 Processor
Greg Brockman Takes Over OpenAI Product Leadership
Greg Brockman Takes Over OpenAI Product Leadership
Microsoft Drops Claude Code for GitHub Copilot CLI
Microsoft Drops Claude Code for GitHub Copilot CLI
OpenAI Brings Personal Finance Dashboard to ChatGPT Pro Users
OpenAI Brings Personal Finance Dashboard to ChatGPT Pro Users
Anthropic Launches $200M AI Project With Gates Foundation
Anthropic Launches $200M AI Project With Gates Foundation
Cybersecurity
New Megalodon Malware Hits Thousands of GitHub Projects
New Megalodon Malware Hits Thousands of GitHub Projects
Microsoft Patches Active Defender Zero Day Vulnerabilities
Microsoft Patches Active Defender Zero Day Vulnerabilities
GitHub Hit by Supply Chain Attack Through VS Code Extension
GitHub Hit by Supply Chain Attack Through VS Code Extension
Langflow Flaw Exploited to Steal AWS Keys and Deploy Botnet
Langflow Flaw Exploited to Steal AWS Keys and Deploy Botnet
Fragnesia Exploit Threatens Major Linux Distributions
Fragnesia Exploit Threatens Major Linux Distributions
Foxconn Hit by Cyberattack as Hackers Claim 8TB Data Theft
Foxconn Hit by Cyberattack as Hackers Claim 8TB Data Theft
Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.