Automatically translated.View original post

The ClayRat malware stole SMS messages and secretly took cameras.

The ClayRat malware stole SMS messages and used a camera to secretly film the Android mobile owner.

In the area of malware risk, it is called that Android users are in a state of "nonstop" from the emergence of new malware, increasing the risk every day, as in this news.

According to a report by the website, Cyber Security News has mentioned the detection of a malware distribution campaign of the victim's machine control type, or a new RAT (Remote Access Trojan) called ClayRat, focused on tackling a group of Android users. This campaign is a new malware subspecies of such malware. The first version of ClayRat's malware was detected in October by a research team from zLabs, the developer of artificial intelligence malware detection tools, or AI, before it was detected by a research team from another anti-malware tool, Zimposium. According to the recent epidemic research team, the malware has already spread around the world.

In order to log in to the victim's machine, the malware will impersonate famous applications such as Youtube, messaging applications, as well as local Russian applications such as taxi services and parking rental services. It is expected that the malware may originate from Russia. These applications will spread through phishing fraudulent websites. The research team has detected up to 25 domains associated with the campaign. In addition, hackers behind it have also used cloud file deposit services such as Dropbox to spread the malware even more widely.

After the malware has entered the victim's machine, during installation, access permissions, short messages (SMS or Short Message Service), and Accessibility Modes are requested to help hackers gain control of the machine. The first step of installation is not the real ClayRat malware, but the Dropper malware created to infiltrate the machine and evade the detection system. The Dropper itself, after entering the machine, decrypts the real payload file encrypted with AES / CBC encryption. By using the Decryption Key embedded during Runtime, it is even more difficult to detect. After successfully installing it, the malware will request access to the above mentioned and start working immediately.

This Accessibility Mode allows malware to disable protection systems such as Google Play Protect and Google Play Store without the victim knowing it. In addition, the malware secretly stores data between lock screens to store data for unlocking screens such as pattern, PIN, and unlock passwords. These data are stored in key SharedPreferences called lock _ password _ storage. These data will be used to unlock the screen using the auto _ unlock command.

In addition to this ability, the malware has the ability to access the camera on the victim's mobile phone to be used to sneak pictures of the victim. With the MediaProjection API, SMS theft from using the requested access permissions in the installation phase, access to dial-in and out records, create a fake notification screen to capture sensitive information that the victim answers to fake notifications.

# Recap 2025 # Take care of yourself # Open budget # Includes IT matters

# Cybersecurity

2025/12/26 Edited to

... Read moreจากประสบการณ์การใช้งานมือถือ Android ผมพบว่าในยุคนี้มัลแวร์อย่าง ClayRat นั้นน่ากลัวเกินกว่าจะมองข้าม โดยเฉพาะการที่มันสามารถแอบถ่ายภาพเจ้าของเครื่องได้ผ่านกล้อง ทำให้ความเป็นส่วนตัวถูกละเมิดอย่างรุนแรง ลงลึกไปอีก มัลแวร์นี้ไม่ได้ทำแค่ขโมยข้อมูล SMS เท่านั้น แต่ยังใช้สิทธิ์ Accessibility เพื่อปิดระบบป้องกันอย่าง Google Play Protect และซ่อนตัวอย่างแนบเนียน ทำให้ผู้ใช้ทั่วไปแทบไม่รู้ตัวเลยว่ามีภัยแฝงอยู่ในเครื่อง วิธีการระบาดที่น่ากลัวคือ มัลแวร์ ClayRat แฝงตัวเป็นแอปชื่อดัง ทั้งแอปส่งข้อความ ยอดนิยม หรือแม้แต่แอปบริการท้องถิ่น ทำให้เราโดนหลอกดาวน์โหลดมาโดยไม่รู้ตัว ผมเองเคยเจอเว็บหลอกลวงที่มีลักษณะคล้ายกับเว็บจริง จึงอยากแนะนำว่า อย่าคลิกลิงก์น่าสงสัยและดาวน์โหลดแอปจากแหล่งที่ไม่น่าเชื่อถือเด็ดขาด อีกเรื่องที่น่ากังวลคือ มัลแวร์ขโมยข้อมูลการปลดล็อกหน้าจอ เช่น รหัส PIN หรือลายเส้นปลดล็อก และนำไปปลดล็อกหน้าจอเองได้อย่างอัตโนมัติ ช่วยให้แฮกเกอร์เข้าถึงข้อมูลสำคัญได้ง่ายยิ่งขึ้น ผมจึงอยากแนะนำทุกคนให้ตั้งค่าความปลอดภัยมือถือให้เคร่งครัด หลีกเลี่ยงการให้สิทธิ์แอปที่ไม่จำเป็นโดยเฉพาะสิทธิ์ Accessibility และใช้แอปแอนตี้ไวรัสที่เชื่อถือได้ รวมทั้งควรสำรองข้อมูลเป็นประจำเพื่อป้องกันความเสียหายในอนาคต สุดท้าย ขอฝากไว้ว่าให้ติดตามข่าวสารด้านไซเบอร์อยู่เสมอและระมัดระวังลิงก์หรือแอปที่ได้รับมาใหม่ๆ เพื่อรักษาความปลอดภัยข้อมูลและความเป็นส่วนตัวของตัวเราเองครับ

Related posts

SO TRUE 🤌✨
#books #booktok #book #bookrecommendations #bookwormsoflemon8 *not mine
BookEuphoria✨📚

BookEuphoria✨📚

15.7K likes

Blind man unexpectedly regains sight only to discover his wife’s secret #foryou #fyp #edit #aftereffects #shortplay
Rubymovies

Rubymovies

1948 likes

Bad Bunny will be e performer at the 2026 Super Bowl LX Halftime Show on Apple - Music. #news #badbunny #SuperBowl #noticiastiktok #MLB
dctetd.uyty

dctetd.uyty

1143 likes

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

9 likes

No wonder Jenna Ortega can’t help but touch Emma Myers in public. Three little details suggest they’re more than just friends. #jennaortega #jemma #wednesday #EmmaMyers #foryou #us
Trendy Fun

Trendy Fun

8 likes

Ex-Royal Marine commando hid on an island. Until he saved a girl.
shadowframes005

shadowframes005

0 likes

Daughter’s Secret Post Unleashes Nightmare on Her Family.
shadowframes005

shadowframes005

163 likes

#foryou #trump
Lividinitvshow2

Lividinitvshow2

0 likes

Part1: Telling the story of "Daddy's Perfect Little Girl" from Ella's first-person perspective #fyp #foryou #movie #edit #usa_tiktok
UUU_EDIT

UUU_EDIT

10.9K likes

PhillieslandAll-StarcloserJhoanDuranaheadofMLBtradedeadline #foryou #movie #fypviral #shorts #usa
Osnsi

Osnsi

63 likes

He Poisoned His Wife…But Something Strange Happened
shadowframes005

shadowframes005

73 likes

Amanda Bynes Looks UNRECOGNIZABLE After Losing 20 Pounds On Ozempic #usa🇺🇸 #viral
Charlie USA

Charlie USA

168 likes

#podcast #podcastclips #tools #fyp #diy #satisfying #story #relaxingvideos #nba
Kalani Vesey

Kalani Vesey

0 likes

Elite Hacker Destroyed His Empire By Forgetting On
Bro, I really forgot to use a VPN 💀 #hacker #cybercrime #fail #tech #arrestedstupidly
arrestedstupidly

arrestedstupidly

1 like

Evil Babysitter Caught on Hidden Camera! (Caught Her!)
Brent Rivera❤️❤️

Brent Rivera❤️❤️

25 likes

A Ben 10 gym audio for you. #fyp #gym #ben10 #ben10omniverse #audio
IzzyywiththeZ

IzzyywiththeZ

0 likes

#tiktok #fyp #movie #tik
user5728346915963

user5728346915963

14 likes

✨ Stand out during the holidays with this combo!
Tonight's combo is one that will make you stand out. Key notes: Honey, vanilla, amber. With a light hint of tobacco. 💌 Brand: @TheTipsyGoatSoapCompany Honey Toffee 💌 Brand: @Jebouri | Arabian Perfumery honey amber 💌 Brand: @Guerlain Tobacco Honey #عطر #عطور #perfumetiktok #
✨it's malware✨

✨it's malware✨

1 like

#varsity #mysterydiners #showcommentary #voiceover #usa
vetekalaanbo7

vetekalaanbo7

123 likes

#film #tiktok #foryou #fyp
Francisinn Qu

Francisinn Qu

1 like

#usa #news #royals #royalsfamilys
Daily News5 Trending❤️

Daily News5 Trending❤️

1 like

#movie #film #jackiechan #jackiech #fyp
di

di

1 like

Check out this website that helps you when you’re feeling uninspired! I walk you thru the process of downloading the svg file to taking it to cricut design space! Happy crafting. #designinspo #creativeart #cricutprojects #svgfiles #CricutTips
VlunaWorks

VlunaWorks

39 likes

SOS!!! Wha do you do if you click a phishing email link… two times?!? So far I have: 1, added two factor sign on 2, changed my passwords 3, stress cried and spiraled But for real. What do you do… how do I know if there is now malware (? Is that what it’s called ?) living on my computer?!?
Alexandra Wildeson

Alexandra Wildeson

2 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

10 Times Stranger Things Stars Flirted So Hard We Forgot #strangerthings4 #strangerthings #finnwolfhard #joekeery #milliebobbybrown
Anna News Channel

Anna News Channel

42 likes

Oscar Esparza Hacker

Oscar Esparza Hacker

0 likes

The Wild Stray Cat That Terrorized My Home 😱🐈 For weeks, my peaceful cat family was under attack. My Hajime cats came home with wounds, trembling in fear - and I didn't understand why. Then, the midnight growls and missing cat food told me something was wrong. That's when I discovered th
Stray Cat Talkz

Stray Cat Talkz

1 like

How to Make a Dyson Sphere in Sandboxels
#dysonsphere #science #sciencegames #gaming #pixelart
R74n

R74n

7 likes

#royals #paratiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii #news #viral #prince
News D

News D

0 likes

Free SVG files for Cricut Design Space. If you’re dealing with crafter’s block, this website has tons of free SVG downloads to spark new project ideas for shirts, stickers, bookmarks, and more. Save this for your next Cricut project and start creating again 💕 #designinspo #creativeart
VlunaWorks

VlunaWorks

3 likes

See more