Executive Summary
In mid-2024, security researchers at Zimperium discovered ClayRat, a rapidly evolving Android spyware campaign targeting users in Russia. Disguised as trusted apps like TikTok and YouTube, ClayRat was spread via phishing websites and Telegram channels, infecting over 600 devices in just three months. Once installed, the spyware leverages Android’s SMS handler permissions to bypass typical security prompts, allowing attackers to covertly access messages, call logs, device information, and even remotely control infected phones. The highly orchestrated campaign abused social engineering, web deception, and obfuscation techniques to remain undetected, and can turn each compromised device into a new attack vector.
The threat’s evolution signals rising global risks, as the campaign’s tactics can easily adapt to new payloads and regions. With increasing use of mobile malware, organizations globally should reassess mobile security controls and user awareness programs to defend against sophisticated, evasive spyware attacks exploiting trust in well-known apps.
Why This Matters Now
ClayRat exemplifies a new wave of highly adaptive mobile malware that exploits trusted brands and evades traditional detection. Given its rapid evolution and ability to bypass Android security, organizations and individuals everywhere face urgent risk of compromise, highlighting the need for robust mobile threat defense and vigilant user education.
Attack Path Analysis
Adversaries distributed ClayRat spyware via phishing websites and social engineering, tricking users into installing trojanized mobile apps. Once installed, the spyware abused Android permissions to escalate privileges, gaining deep access to device data. The malware may then attempt lateral movement by exploiting compromised SMS handlers or spreading links to contacts, increasing its footprint. Command and Control was maintained through covert outbound connections to remote servers, allowing ongoing attacker access. Sensitive data including messages, call logs, and device information was stealthily exfiltrated using encrypted or obfuscated network traffic. Finally, attackers achieved impact by hijacking device capabilities, such as covertly taking photos or making calls, causing surveillance and potential reputational or operational harm.
Kill Chain Progression
Initial Compromise
Description
ClayRat spyware was introduced onto devices through phishing websites and impersonated popular apps, leveraging social engineering to convince victims to install the malicious application.
Related CVEs
CVE-2023-20963
CVSS 7.8An issue in Android's SMS handler role allows malicious apps to gain broad access to SMS content and messaging functions without individual runtime permissions.
Affected Products:
Google Android – 13.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Drive-by Compromise
Phishing: Spearphishing via Service
Download New Code at Runtime
Input Capture
Exfiltration Over Command and Control Channel
Deliver Malicious App via Authorized Store or Web
Obfuscated Files or Information
Access Sensitive Data in Device Logs or SMS
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication for User Access
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management
Control ID: Article 9(2)
CISA Zero Trust Maturity Model 2.0 – Continuous Discovery and Security Enforcement on Devices
Control ID: Device: Asset Inventory and Control
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical mobile infrastructure vulnerability to ClayRat spyware targeting Android devices, requiring enhanced east-west traffic security and zero trust segmentation implementations.
Financial Services
High-risk exposure through mobile banking applications being impersonated by ClayRat, necessitating robust threat detection and encrypted traffic protection for customer data.
Government Administration
Significant national security implications from Russian-origin spyware potentially targeting government mobile devices, demanding comprehensive multicloud visibility and anomaly response capabilities.
Health Care / Life Sciences
HIPAA compliance violations risk from ClayRat's SMS handler abuse accessing sensitive patient communications, requiring immediate egress security and policy enforcement measures.
Sources
- Russian spyware ClayRat is spreading, evolving quickly, according to Zimperiumhttps://cyberscoop.com/russian-spyware-clayrat-is-spreading-evolving-quickly-according-to-zimperium/Verified
- This devious Android malware spoofs WhatsApp, TikTok and more - here's how to stay safehttps://www.techradar.com/pro/security/this-devious-android-malware-spoofs-whatsapp-tiktok-and-more-heres-how-to-stay-safeVerified
- ClayRat Android Spyware Campaign Exposed | Zimperium - TechNaduhttps://www.technadu.com/clayrat-spyware-campaign-targets-android-users-via-telegram-and-fake-whatsapp-tiktok-youtube-sites/611123/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, robust egress controls, and continuous anomaly detection at the cloud network layer would have helped contain ClayRat’s propagation, limit unauthorized outbound connections, and identify suspicious device behaviors. CNSF-aligned controls can prevent lateral movement, block data exfiltration, and provide visibility into high-risk traffic paths.
Control: Multicloud Visibility & Control
Mitigation: Heightened detection and alerting on unauthorized or suspicious app downloads from unknown sources.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection of abnormal permission requests or unauthorized attempts to access sensitive data.
Control: Zero Trust Segmentation
Mitigation: Prevents unapproved east-west communication between devices, containing intra-network spread.
Control: Cloud Firewall (ACF) & Inline IPS (Suricata)
Mitigation: Blocks command and control traffic via outbound filtering and threat intelligence inspection.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data exfiltration by enforcing strict egress policies and anomaly-driven alerts.
Early detection of unusual device behavior and potential automated response to limit attacker actions.
Impact at a Glance
Affected Business Functions
- Communications
- Data Security
- User Privacy
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive user data including SMS messages, call logs, device information, and photos taken by the front-facing camera.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust segmentation to prevent lateral movement and contain compromised devices.
- • Enforce robust egress security policies with continuous monitoring for anomalous outbound traffic.
- • Implement centralized multicloud visibility to detect suspicious application downloads and privilege escalations.
- • Enable anomaly-driven threat detection and real-time response for rapid mitigation of novel malware behaviors.
- • Regularly update inline IPS and firewall policies with current threat intelligence to block C2 infrastructure and exfiltration attempts.



