Cybersecurity

📱🔥 ClayRat Evolves: New Android Spyware Breaks Into Devices, Steals SMS, Unlocks Screens, and Hijacks Cameras in Real Time

December 13, 20253 min read

A new and deeply invasive strain of ClayRat Android spyware has surfaced — and it’s one of the most dangerous mobile surveillance tools we’ve seen in years. This variant doesn’t just peek at your device… it owns it.

What started as a reconnaissance-grade spyware family has rapidly evolved into a full device-takeover platform, weaponizing Android’s Accessibility Services and Default SMS privileges to achieve a level of compromise that borders on total digital puppeteering.

Discovered by zLabs researchers, this upgraded ClayRat strain turns an Android device into a 24/7 surveillance asset — and it does so quietly, cleverly, and with ruthless efficiency.


🧠 ClayRat’s New Superpower: Dual Privilege Exploitation

The latest ClayRat variant abuses two of Android’s most sensitive system layers:

1️ Accessibility Services

This gives the malware human-level control — taps, swipes, button presses, UI interactions, and even the ability to keep the user from shutting the device down.

2️ Default SMS Privilege

This grants ClayRat full access to messages, MFA codes, OTPs, and notification content.

Together, these privileges transform ClayRat into an unstoppable mobile cyberweapon.


🔐 Full Device Takeover: What ClayRat Can Do

ClayRat isn’t just spying — it’s simulating the victim.

Keylogging at System Level

  • PINs

  • Passwords

  • Pattern locks
    Captured with flawless accuracy.

Automatic Device Unlock

Once it learns your PIN, ClayRat unlocks your phone at will.

Stealth Screen Recording (MediaProjection API)

Hidden, persistent, real-time screen capture using a ForegroundService that never dies.

Fake Overlays to Mask Activity

It throws up fake system update screens, battery alerts, and overlays to hide its operations.

Block Device Shutdown or Uninstall

Through simulated taps, ClayRat literally prevents victims from powering off or removing the malware.

This isn’t spyware. This is digital hostage-taking.


📸 Surveillance Beyond Screens: Photos, SMS, Calls & Everything Else

ClayRat’s command framework includes nearly 40 remote instructions, enabling:

  • SMS interception

  • MFA harvesting

  • Call log extraction

  • Camera activation

  • Photo capture

  • Device info exfiltration

  • Mass messaging to victim contacts

  • Remote surveillance of corporate apps

It collects passwords, documents, internal messages, financial data — anything displayed or typed on the screen.

For enterprises, this is catastrophic.


🕵️‍♂️ ClayRat’s Disguises: Apps, APKs & Phishing Sites

ClayRat spreads through a multi-vector distribution campaign:

  • Fake video streaming apps

  • Fake messaging apps

  • Russian-language taxi & parking apps

  • Fraudulent “YouTube” copycat domains

  • Spoofed automotive diagnostic tool sites

  • Malicious Dropbox-hosted APKs

Researchers identified 25+ phishing domains and more than 700 APK variants, signaling a massive, well-funded operation.


🧩 Technical Breakdown: How ClayRat Deploys Itself

ClayRat uses a dropper technique inherited from earlier samples:

  • Stores encrypted payloads in assets

  • Uses AES/CBC with embedded keys

  • Decrypts and deploys the malware at runtime

  • Immediately requests SMS + Accessibility

  • Auto-disables Google Play Protect using scripted taps

Yes — the malware taps the screen for you.
This is next-level mobile threat engineering.


🏢 Enterprise Impact: BYOD Nightmare Scenario

For organizations relying on bring-your-own-device programs, ClayRat is a direct threat to:

  • MFA infrastructure

  • Email accounts

  • Corporate messaging tools

  • Remote access apps

  • Document and CRM systems

  • Employee identity integrity

Once a device is compromised, attackers can impersonate employees, harvest internal data, intercept credentials, and escalate into corporate environments.

ClayRat isn’t targeting individuals.
It’s targeting organizations through individuals.


Elliptic Systems’ Take

ClayRat is a turning point in mobile malware evolution — moving from basic spying to full-spectrum device domination. Its ability to block shutdowns, hijack system privileges, and automate touches with surgical precision makes it one of the most dangerous Android spyware variants circulating today.

This threat forces organizations to rethink mobile security entirely — especially BYOD policies.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog