Threat Management, Threat Intelligence, Malware

Student arrested over ClayRat subscription scheme

handcuffs sit on the keyboard of a laptop. cybercrime

An Android spyware operation known as ClayRat that briefly gained traction in Russia has imploded within months of its launch, undone by security blunders and the arrest of its suspected developer, according to The Record, a news site by cybersecurity firm Recorded Future.

The malware was designed to intercept SMS, access contacts, capture screens, and take remote control of infected devices.

It surfaced in October 2025 and expanded quickly, with security firm Zimperium identifying more than 600 samples and around 50 droppers over three months. But by December, all known command servers were offline, according to Russian cybersecurity firm Solar, a Rostelecom subsidiary.

The shutdown appears tied to the arrest of a student in Krasnodar who allegedly marketed ClayRat via Telegram with weekly and monthly subscription plans or a 15% revenue cut.

Researchers said the operation was riddled with mistakes: passwords stored in plaintext, weak code obfuscation, and predictable distribution through phishing sites impersonating WhatsApp, TikTok, and Russian taxi apps. Solar noted the malware's collapse mirrors that of Gorilla, a banking trojan that also folded quickly after its operators made similar errors.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds