clayrat
ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia.
Profile source: Mallory opens in a new tabclayrat
Family profile
ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia. It has been distributed through counterfeit Telegram channels and phishing pages that impersonate widely used consumer applications and services in order to trick victims into sideloading malicious Android packages. The operation is notable for combining mobile-focused social engineering with surveillance and remote-access capabilities aimed at harvesting sensitive user data and enabling direct interaction with compromised devices.
Reported ClayRat capabilities include theft of SMS messages, notifications, and call logs, as well as device surveillance and remote actions such as taking photos, sending messages, and placing calls from infected phones. Its tradecraft aligns with broader mobile spyware activity that abuses trust in messaging and social platforms, relies on app impersonation, and targets the device rather than attempting to break end-to-end encryption directly.
ClayRat has been described as an Android spyware campaign rather than a formally attributed nation-state intrusion set, and publicly available information does not establish a definitive state sponsor. It has, however, been discussed alongside commercial spyware and mobile surveillance threats affecting messaging-app users. ClayRat has also been referenced on a leak and collaboration platform called THE PERSEPHONE, where it appeared alongside VFVCT and RasCorp Group under a banner of “United Cyber Operations,” suggesting at least claimed association or cooperation within a broader cybercriminal or hacktivist ecosystem. This relationship should be treated cautiously absent stronger corroboration.
Known aliases include clayrat and clayrat_operators. The most widely recognized name used by defenders and researchers is ClayRat.
MITRE ATT&CK