An Android spyware operation known as ClayRat that briefly gained traction in Russia has imploded within months of its launch, undone by security blunders and the arrest of its suspected developer, according to The Record, a news site by cybersecurity firm Recorded Future.
The malware was designed to intercept SMS, access contacts, capture screens, and take remote control of infected devices.
It surfaced in October 2025 and expanded quickly, with security firm Zimperium identifying more than 600 samples and around 50 droppers over three months. But by December, all known command servers were offline, according to Russian cybersecurity firm Solar, a Rostelecom subsidiary.
The shutdown appears tied to the arrest of a student in Krasnodar who allegedly marketed ClayRat via Telegram with weekly and monthly subscription plans or a 15% revenue cut.
Researchers said the operation was riddled with mistakes: passwords stored in plaintext, weak code obfuscation, and predictable distribution through phishing sites impersonating WhatsApp, TikTok, and Russian taxi apps. Solar noted the malware's collapse mirrors that of Gorilla, a banking trojan that also folded quickly after its operators made similar errors.
The malware was designed to intercept SMS, access contacts, capture screens, and take remote control of infected devices.
It surfaced in October 2025 and expanded quickly, with security firm Zimperium identifying more than 600 samples and around 50 droppers over three months. But by December, all known command servers were offline, according to Russian cybersecurity firm Solar, a Rostelecom subsidiary.
The shutdown appears tied to the arrest of a student in Krasnodar who allegedly marketed ClayRat via Telegram with weekly and monthly subscription plans or a 15% revenue cut.
Researchers said the operation was riddled with mistakes: passwords stored in plaintext, weak code obfuscation, and predictable distribution through phishing sites impersonating WhatsApp, TikTok, and Russian taxi apps. Solar noted the malware's collapse mirrors that of Gorilla, a banking trojan that also folded quickly after its operators made similar errors.
