This devious Android malware spoofs WhatsApp, TikTok and more – here’s how to stay safe

  • ClayRat malware mimics popular apps to steal data and spread via victim contact lists
  • It abuses Android’s SMS handler role to bypass permissions and access sensitive content
  • Over 600 variants found; users should stick to trusted app stores and use antivirus tools

A new Android malware variant is posing as popular apps, stealing sensitive files and propagating further.

Experts from Zimperium revealed ClayRat, targeting primarily Russian users by spoofing popular Android apps such as WhatsApp, TikTok, Google Photos, or YouTube, distributed mostly through Telegram channels and standalone phishing sites.

Through typosquatting, the phishing sites trick victims into thinking they’re visiting a legitimate page and then redirects them to Telegram channels where the malware is hosted.

How to stay safe

Once the victims install ClayRat, it abuses Android’s default SMS handler role, allowing it to bypass standard runtime permission prompts and gain access to sensitive data without raising alarms.

“When an app is granted this role, it gains broad access to SMS content and messaging functions, allowing the spyware to read, store, and forward text messages at scale,” Zimperium explained. “Unlike individual runtime permissions that require per-capability approval, the SMS handler role consolidates multiple powerful capabilities into a single authorization step.”

The sensitive data it is looking to exfiltrate includes SMS messages, call logs, device data, and photos taken by the front-facing camera. Once it steals whatever information it finds, the malware propagates further by sending a malicious download link to every contact in the victim’s phonebook, turning the infected device into a powerful distribution hub.

Whoever is behind ClayRat is active, too, Zimperium said. In the last three months alone, the researchers found more than 600 variants and 50 different droppers, each with a separate obfuscation layer. However, they don’t think the practice is unique to this threat actor, but rather proof of the “increasing speed and sophistication” of today’s mobile threats.

“ClayRat demonstrates how attackers are evolving faster than ever, combining social engineering, self-propagation, and system abuse to maximize reach,” said Shridhar Mittal, CEO of Zimperium.

To protect against these sorts of threats, you should only download apps from trusted sources, such as Google’s Play Store, or Apple’s App Store.

A little due diligence wouldn’t hurt, either, by checking the number of downloads, the overall review score, and a few user comments.

Finally, having a mobile antivirus solution set up always helps, and so is being mindful of the permissions granted to different apps.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Netgear Orbi 373: affordable and easy-to-use mesh Wi-Fi system for larger homes

Netgear Orbi 373: One-minute reviewNetgear’s new management continues its quest to provide more affordable options for home users who want to upgrade their Wi-Fi....

Hackers are exploiting OAuth loophole for persistent access – and resetting your password won’t save you

Researchers have observed attackers weaponizing OAuth apps Attackers gain access that persists even through password changes and MFAThis isn't just a proof of concept...

Get $100 off the near-perfect OnePlus 13 with this code for a limited time

With the imminent release of the OnePlus 15, we're being treated to a super sweet discount on the phone that it'll supersede. That means...

Oracle Red Bull is securing the win with 1Password – a credential halo balancing speed and security on and off the track

Formula 1 is a notoriously high-stakes sport, but the danger doesn’t stop when the chequered flag waves at the end of the race weekend.Engineering,...

“A first step in Europe” – Proton slams Switzerland’s new surveillance bill at the United Nations Forum

Proton Mail has reiterated its opposition to Switzerland's new surveillance billThe bill will force VPN and messaging apps to identify and retain user dataProton...

Settlers, herd your sheep – Netflix reveals Catan movies and TV series, and I know just how they should start

Think you've mastered the Catan board game? Well, Netflix is about take the experience to the small screen, having secured global rights to multiple...

Smart bed owners experience AWS outage nightmare as they’re left sweating and stuck in upright position

Smart bed owners were hit by this week's big AWS outageOwners of the Eight Sleep Pod reported overheating and being stuck uprightEight Sleep tells...

Panasonic just launched a cheaper big-screen OLED TV, but still with the high-end sound and processing of its flagship Z95B

Integrated Fire TV and ATSC 3.0 supportTons of gamer-friendly features including 144Hz, G-SYNC, Freesync v2 Premium and VRR$2,499, orders live from 27 OctoberPanasonic's excellent...

NYT Connections hints and answers for Thursday, October 23 (game #865)

Looking for a different day?A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people...

NYT Strands hints and answers for Thursday, October 23 (game #599)

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people...