Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 4 hostnames
ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia.
Profile source: Mallory opens in a new tabclayrat
ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia. It has been distributed through counterfeit Telegram channels and phishing pages that impersonate widely used consumer applications and services in order to trick victims into sideloading malicious Android packages. The operation is notable for combining mobile-focused social engineering with surveillance and remote-access capabilities aimed at harvesting sensitive user data and enabling direct interaction with compromised devices.
Reported ClayRat capabilities include theft of SMS messages, notifications, and call logs, as well as device surveillance and remote actions such as taking photos, sending messages, and placing calls from infected phones. Its tradecraft aligns with broader mobile spyware activity that abuses trust in messaging and social platforms, relies on app impersonation, and targets the device rather than attempting to break end-to-end encryption directly.
ClayRat has been described as an Android spyware campaign rather than a formally attributed nation-state intrusion set, and publicly available information does not establish a definitive state sponsor. It has, however, been discussed alongside commercial spyware and mobile surveillance threats affecting messaging-app users. ClayRat has also been referenced on a leak and collaboration platform called THE PERSEPHONE, where it appeared alongside VFVCT and RasCorp Group under a banner of βUnited Cyber Operations,β suggesting at least claimed association or cooperation within a broader cybercriminal or hacktivist ecosystem. This relationship should be treated cautiously absent stronger corroboration.
Known aliases include clayrat and clayrat_operators. The most widely recognized name used by defenders and researchers is ClayRat.
C2 tracking
Derp observations, rolling seven-day window
Samples
93893eba96702f963b6e005e8b9ab046dae883046c9673e8ac0caa73194bfa74 1e8c7934272a2a381ee947f8aefef602a55802181b0c9584029e354a42f49f2e 2625df6b52a737543cbf542325dfcfc6208d2be67c4aa0cd26b6a0e3aa5bdb33 ffe908b9697f064fab126514d6830ecdf7687557035d9940230086b13df6d8f2 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.