ClayRat is an Android spyware operation associated with malicious mobile applications distributed through counterfeit Telegram channels and lookalike phishing pages impersonating widely used consumer platforms. The operation has primarily targeted users in Russia and is designed to compromise mobile devices and harvest sensitive user data. Reported functionality includes theft of SMS messages, notifications, and call logs, as well as device abuse capabilities such as taking photos and sending messages or placing calls from infected devices. ClayRat relies on social engineering and app impersonation for initial access, presenting spyware-laced Android applications as legitimate services such as messaging, media, and social platforms. This tradecraft aligns with broader mobile spyware activity focused on compromising communications and personal data without exploiting encryption directly. ClayRat has been referenced alongside VFVCT and RasCorp Group on the THE PERSEPHONE platform, where the groups were presented as cooperating under a “United Cyber Operations” banner, indicating at minimum an advertised association within a shared leak and communications ecosystem. Available reporting supports ClayRat as a spyware-focused threat actor or operator set rather than a ransomware group. Its observed behavior is consistent with credential and data collection, surveillance, and post-compromise device misuse on Android targets. High-confidence reporting does not establish a definitive state sponsor or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the groups collaborating on THE PERSEPHONE shared leak platform under a joint operational environment.
ClayRat has resurfaced with expanded features and techniques, indicating ongoing development and activity.
ClayRat operators distribute Android spyware via counterfeit Telegram channels and phishing sites, targeting users in Russia.
ClayRat operators target Russian users via Telegram channels and phishing pages, impersonating popular apps to distribute spyware and steal sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.