Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried the only agentive browser that runs native AI – and found only one downside

    November 7, 2025

    Get 4 Free iPhone 17 or Galaxy S25 Phones from T-Mobile Right Now – Here’s How

    November 7, 2025

    She has 3 secrets to doubling the revenue of your mom’s business

    November 7, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New Android spyware Clearat mimics WhatsApp, TikTok, YouTube
    Security

    New Android spyware Clearat mimics WhatsApp, TikTok, YouTube

    PineapplesUpdateBy PineapplesUpdateOctober 9, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Android spyware Clearat mimics WhatsApp, TikTok, YouTube
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New Android spyware Clearat mimics WhatsApp, TikTok, YouTube

    A new Android spyware called Clearat is luring potential victims in the form of popular apps and services like WhatsApp, Google Photos, TikTok and YouTube.

    The malware is targeting Russian users through Telegram channels and malicious websites that appear legitimate. It can steal SMS, messages, call logs, notifications, take photos and even make phone calls.

    Malware researchers at mobile security company Zimperium say they have documented more than 600 samples and 50 different droppers over the past three months, indicating an active effort by the attacker to scale up the operation.

    claret campaign

    The Clarett campaign, named after the malware’s command and control (C2) servers, uses carefully crafted phishing portals and registered domains that closely mimic legitimate service pages.

    These sites host or redirect visitors to Telegram channels where Android package files (APKs) are provided to unwitting victims.

    To add legitimacy to these sites, threat actors have added fake comments, inflated download numbers, and used a fake Play Store-like UX with step-by-step instructions on how to sideload APKs and bypass Android’s security warnings.

    Fake update is loading spyware in the background
    Fake update is loading spyware in the background
    Source: Zimperium

    According to Zimperium, some of the Claret malware samples act as droppers, where the app the user sees is a fake Play Store update screen and an encrypted payload is hidden in the app’s properties.

    The malware nests in the device using a “session-based” installation method to bypass Android 13+ restrictions and reduce user suspicion.

    “This session-based installation method reduces the perceived risk and increases the likelihood that spyware will be installed as a result of a webpage visit,” the researchers say.

    Once activated on a device, the malware can use the new host to spread to more victims by using it as a springboard to send SMS to the victim’s contact list.

    Telegram channel dropper spreading
    Telegram channel spreading claret dropper
    Source: Zimperium

    Spyware Capabilities

    The Clearat spyware takes over the role of the default SMS handler on infected devices, which allows it to read all incoming and stored SMS, intercept them before other apps can, and modify the SMS database.

    claret becoming the default sms handler
    claret becoming the default sms handler
    Source: Zimperium

    The spyware establishes communication with C2, which is AES-GCM encrypted in its latest versions, and then receives one of 12 supported commands:

    • get_apps_list – send list of installed apps to C2
    • get_calls – send call logs
    • get_camera – take a front-camera photo and send it to the server
    • get_sms_list – pull out SMS messages
    • MassSMS – send mass SMS to all contacts
    • send_sms / make_call – send SMS or make a call from the device
    • notifications/get_push_notifications – Capture notifications and push data
    • get_device_info – collect device information
    • get_proxy_data – Get a proxy WebSocket URL, add device ID, and initialize a connection object (converts HTTP/HTTPS to WebSocket and schedules tasks)
    • Retransmission – resend an SMS to the number received from C2

    When the necessary permissions are granted, the spyware automatically collects the contacts and programmatically prepares and sends SMS messages to each contact for mass dissemination.

    As a member of the App Defense Alliance, Zimperium shared Full IoCs With Google, Play Protect now blocks known and new variants of the Clearit spyware.

    However, the researchers highlight that the campaign is very large, with more than 600 samples on record in three months.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    Android Clearat mimics spyware Tiktok WhatsApp YouTube
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleStartup battlefield company SpotitEarly trains dogs and AI to sniff out common cancers
    Next Article The most important OpenAI announcement you probably missed at DevDay 2025
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Replika founder raises $20M pre-seed for Wabi, the ‘Youtube of apps’

    November 5, 2025
    Startups

    This $400 Android phone with a paper-like display is boringly amazing — and I can’t let it go

    November 3, 2025
    Startups

    Buying an Android smartwatch? I found one that is highly functional and affordable

    November 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried the only agentive browser that runs native AI – and found only one downside

    November 7, 2025

    Get 4 Free iPhone 17 or Galaxy S25 Phones from T-Mobile Right Now – Here’s How

    November 7, 2025

    She has 3 secrets to doubling the revenue of your mom’s business

    November 7, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.