Cybersecurity & Privacy — 2026-03-23

Russia-Linked ClayRAT Malware Operation Collapses After Developer's Arrest

ClayRAT, an Android spyware operation capable of intercepting SMS, recording screens, and executing remote commands, collapsed after the arrest of its student developer in Krasnodar, Russia. The operation ran from October 2025 to December, producing 600+ malware samples targeting primarily Russian users via phishing sites impersonating WhatsApp, Google Photos, and TikTok. Poor operational security — plaintext passwords, weak obfuscation, predictable distribution — accelerated its demise. The subscription model charged $90/week or $300/month via Telegram.

1 sources
  1. Russia-linked malware operation collapses after security failures, developer's arrest - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE