Skip to content
Malware family

clayrat

ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia.

Profile source: Mallory opens in a new tab

clayrat

Family profile

ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia. It has been distributed through counterfeit Telegram channels and phishing pages that impersonate widely used consumer applications and services in order to trick victims into sideloading malicious Android packages. The operation is notable for combining mobile-focused social engineering with surveillance and remote-access capabilities aimed at harvesting sensitive user data and enabling direct interaction with compromised devices.

Reported ClayRat capabilities include theft of SMS messages, notifications, and call logs, as well as device surveillance and remote actions such as taking photos, sending messages, and placing calls from infected phones. Its tradecraft aligns with broader mobile spyware activity that abuses trust in messaging and social platforms, relies on app impersonation, and targets the device rather than attempting to break end-to-end encryption directly.

ClayRat has been described as an Android spyware campaign rather than a formally attributed nation-state intrusion set, and publicly available information does not establish a definitive state sponsor. It has, however, been discussed alongside commercial spyware and mobile surveillance threats affecting messaging-app users. ClayRat has also been referenced on a leak and collaboration platform called THE PERSEPHONE, where it appeared alongside VFVCT and RasCorp Group under a banner of β€œUnited Cyber Operations,” suggesting at least claimed association or cooperation within a broader cybercriminal or hacktivist ecosystem. This relationship should be treated cautiously absent stronger corroboration.

Known aliases include clayrat and clayrat_operators. The most widely recognized name used by defenders and researchers is ClayRat.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 23, 2026
Feed role
C2
Host form
0 IP / 4 hostnames

Leading locations

  • US3
  • PL1

Leading providers

  • QWINS LTD1

Infrastructure traits

  • Hosting 1
  • Residential Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

clayrat in ATT&CK

2 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.