
📱🔥 ClayRat Evolves: New Android Spyware Breaks Into Devices, Steals SMS, Unlocks Screens, and Hijacks Cameras in Real Time
A new and deeply invasive strain of ClayRat Android spyware has surfaced — and it’s one of the most dangerous mobile surveillance tools we’ve seen in years. This variant doesn’t just peek at your device… it owns it.
What started as a reconnaissance-grade spyware family has rapidly evolved into a full device-takeover platform, weaponizing Android’s Accessibility Services and Default SMS privileges to achieve a level of compromise that borders on total digital puppeteering.
Discovered by zLabs researchers, this upgraded ClayRat strain turns an Android device into a 24/7 surveillance asset — and it does so quietly, cleverly, and with ruthless efficiency.
🧠 ClayRat’s New Superpower: Dual Privilege Exploitation
The latest ClayRat variant abuses two of Android’s most sensitive system layers:
1️⃣ Accessibility Services
This gives the malware human-level control — taps, swipes, button presses, UI interactions, and even the ability to keep the user from shutting the device down.
2️⃣ Default SMS Privilege
This grants ClayRat full access to messages, MFA codes, OTPs, and notification content.
Together, these privileges transform ClayRat into an unstoppable mobile cyberweapon.
🔐 Full Device Takeover: What ClayRat Can Do
ClayRat isn’t just spying — it’s simulating the victim.
✔ Keylogging at System Level
PINs
Passwords
Pattern locks
Captured with flawless accuracy.
✔ Automatic Device Unlock
Once it learns your PIN, ClayRat unlocks your phone at will.
✔ Stealth Screen Recording (MediaProjection API)
Hidden, persistent, real-time screen capture using a ForegroundService that never dies.
✔ Fake Overlays to Mask Activity
It throws up fake system update screens, battery alerts, and overlays to hide its operations.
✔ Block Device Shutdown or Uninstall
Through simulated taps, ClayRat literally prevents victims from powering off or removing the malware.
This isn’t spyware. This is digital hostage-taking.
📸 Surveillance Beyond Screens: Photos, SMS, Calls & Everything Else
ClayRat’s command framework includes nearly 40 remote instructions, enabling:
SMS interception
MFA harvesting
Call log extraction
Camera activation
Photo capture
Device info exfiltration
Mass messaging to victim contacts
Remote surveillance of corporate apps
It collects passwords, documents, internal messages, financial data — anything displayed or typed on the screen.
For enterprises, this is catastrophic.
🕵️♂️ ClayRat’s Disguises: Apps, APKs & Phishing Sites
ClayRat spreads through a multi-vector distribution campaign:
Fake video streaming apps
Fake messaging apps
Russian-language taxi & parking apps
Fraudulent “YouTube” copycat domains
Spoofed automotive diagnostic tool sites
Malicious Dropbox-hosted APKs
Researchers identified 25+ phishing domains and more than 700 APK variants, signaling a massive, well-funded operation.
🧩 Technical Breakdown: How ClayRat Deploys Itself
ClayRat uses a dropper technique inherited from earlier samples:
Stores encrypted payloads in assets
Uses AES/CBC with embedded keys
Decrypts and deploys the malware at runtime
Immediately requests SMS + Accessibility
Auto-disables Google Play Protect using scripted taps
Yes — the malware taps the screen for you.
This is next-level mobile threat engineering.
🏢 Enterprise Impact: BYOD Nightmare Scenario
For organizations relying on bring-your-own-device programs, ClayRat is a direct threat to:
MFA infrastructure
Email accounts
Corporate messaging tools
Remote access apps
Document and CRM systems
Employee identity integrity
Once a device is compromised, attackers can impersonate employees, harvest internal data, intercept credentials, and escalate into corporate environments.
ClayRat isn’t targeting individuals.
It’s targeting organizations through individuals.
Elliptic Systems’ Take
ClayRat is a turning point in mobile malware evolution — moving from basic spying to full-spectrum device domination. Its ability to block shutdowns, hijack system privileges, and automate touches with surgical precision makes it one of the most dangerous Android spyware variants circulating today.
This threat forces organizations to rethink mobile security entirely — especially BYOD policies.
