ClayRat is an Android spyware family and associated operator set primarily observed targeting users in Russia. It has been distributed through counterfeit Telegram channels and phishing pages that impersonate widely used consumer applications and services in order to trick victims into sideloading malicious Android packages. The operation is notable for combining mobile-focused social engineering with surveillance and remote-access capabilities aimed at harvesting sensitive user data and enabling direct interaction with compromised devices. Reported ClayRat capabilities include theft of SMS messages, notifications, and call logs, as well as device surveillance and remote actions such as taking photos, sending messages, and placing calls from infected phones. Its tradecraft aligns with broader mobile spyware activity that abuses trust in messaging and social platforms, relies on app impersonation, and targets the device rather than attempting to break end-to-end encryption directly. ClayRat has been described as an Android spyware campaign rather than a formally attributed nation-state intrusion set, and publicly available information does not establish a definitive state sponsor. It has, however, been discussed alongside commercial spyware and mobile surveillance threats affecting messaging-app users. ClayRat has also been referenced on a leak and collaboration platform called THE PERSEPHONE, where it appeared alongside VFVCT and RasCorp Group under a banner of “United Cyber Operations,” suggesting at least claimed association or cooperation within a broader cybercriminal or hacktivist ecosystem. This relationship should be treated cautiously absent stronger corroboration. Known aliases include clayrat and clayrat_operators. The most widely recognized name used by defenders and researchers is ClayRat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the groups collaborating on THE PERSEPHONE shared leak platform under a joint operational environment.
ClayRat has resurfaced with expanded features and techniques, indicating ongoing development and activity.
ClayRat operators distribute Android spyware via counterfeit Telegram channels and phishing sites, targeting users in Russia.
ClayRat operators target Russian users via Telegram channels and phishing pages, impersonating popular apps to distribute spyware and steal sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.