This devious Android malware spoofs WhatsApp, TikTok and more – here’s how to stay safe
- ClayRat malware mimics popular apps to steal data and spread via victim contact lists
- It abuses Android’s SMS handler role to bypass permissions and access sensitive content
- Over 600 variants found; users should stick to trusted app stores and use antivirus tools
A new Android malware variant is posing as popular apps, stealing sensitive files and propagating further.
Experts from Zimperium revealed ClayRat, targeting primarily Russian users by spoofing popular Android apps such as WhatsApp, TikTok, Google Photos, or YouTube, distributed mostly through Telegram channels and standalone phishing sites.
Through typosquatting, the phishing sites trick victims into thinking they’re visiting a legitimate page and then redirects them to Telegram channels where the malware is hosted.
How to stay safe
Once the victims install ClayRat, it abuses Android’s default SMS handler role, allowing it to bypass standard runtime permission prompts and gain access to sensitive data without raising alarms.
“When an app is granted this role, it gains broad access to SMS content and messaging functions, allowing the spyware to read, store, and forward text messages at scale,” Zimperium explained. “Unlike individual runtime permissions that require per-capability approval, the SMS handler role consolidates multiple powerful capabilities into a single authorization step.”
The sensitive data it is looking to exfiltrate includes SMS messages, call logs, device data, and photos taken by the front-facing camera. Once it steals whatever information it finds, the malware propagates further by sending a malicious download link to every contact in the victim’s phonebook, turning the infected device into a powerful distribution hub.
Whoever is behind ClayRat is active, too, Zimperium said. In the last three months alone, the researchers found more than 600 variants and 50 different droppers, each with a separate obfuscation layer. However, they don’t think the practice is unique to this threat actor, but rather proof of the “increasing speed and sophistication” of today’s mobile threats.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“ClayRat demonstrates how attackers are evolving faster than ever, combining social engineering, self-propagation, and system abuse to maximize reach,” said Shridhar Mittal, CEO of Zimperium.
To protect against these sorts of threats, you should only download apps from trusted sources, such as Google’s Play Store, or Apple’s App Store.
A little due diligence wouldn’t hurt, either, by checking the number of downloads, the overall review score, and a few user comments.
Finally, having a mobile antivirus solution set up always helps, and so is being mindful of the permissions granted to different apps.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
You might also like
ClayRat malware mimics popular apps to steal data and spread via victim contact lists It abuses Android’s SMS handler role to bypass permissions and access sensitive content Over 600 variants found; users should stick to trusted app stores and use antivirus tools A new Android malware variant is posing as…
Recent Posts
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
- NordVPN Coupons and Deals: 77% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023