Advertisement · 728 × 90
#
Hashtag
#ClayRat
Advertisement · 728 × 90
Preview
New Android Malware SeedSnatcher and FvncBot Found By Experts New Android malware found Researchers have revealed details of two Android malware strains called SeedSnatcher and FvncBot. Upgraded version of ClayRat was also found in the wild.  About the malware  FvncBot works as a security app built by mBank and attacks mobile banking users in Poland. The malware is written from scratch and is different from other banking trojans such as ERMAC whose source codes have been leaked. According to Intel 471, the malware "implemented multiple features including keylogging by abusing Android's accessibility services, web-inject attacks, screen streaming and hidden virtual network computing (HVNC) to perform successful financial fraud." Like the Albiriox banking malware, this trojan is shielded by a service called apk0day that Golden Crypt offers. Attack tactic  After the dropper app is launched, users are asked to download a Google Play component for security of the app. But in reality, it deploys the malware via session-based approach which other actors adopt to escape accessibility restrictions on Android devices version 13 and above. According to Intel 471, "During the malware runtime, the log events were sent to the remote server at the naleymilva.it.com domain to track the current status of the bot." After this, the malware asks victims for accessibility services permission, it then gets privileges and connects to an external server.  Malware capabilities  FvncBot also triggers a text mode to analyze the device screen layout and content even in cases where an app doesn't allow screenshots by setting the FLAG_SECURE option.  Experts don't yet know how FvncBot is getting widespread, but Android banking trojans leverage third-party app stores and SMS phishing as a distribution vector.  According to Intel 471, "Android's accessibility service is intended to aid users with disabilities, but it also can give attackers the ability to know when certain apps are launched and overwrite the screen's display."  The firm added that the sample was built to "target Polish-speaking users, it is plausible we will observe this theme shifting to target other regions or to impersonate other Polish institutions." Beyond the immediate threat to banking and cryptocurrency users, the emergence of FvncBot, SeedSnatcher, and the upgraded ClayRat underscores a troubling evolution in mobile-malware design: an increasing shift toward “full-device takeover” rather than mere credential theft. By exploiting legitimate features, such as Android’s accessibility services, screen-streaming APIs, and overlay permissions, these trojans can invisibly hijack almost every function of a smartphone: logging keystrokes, intercepting SMS-delivered 2FA codes, capturing screen contents even when apps try to block screenshots, and executing arbitrary commands as though the real user were interacting with the device.  This marks a new class of threat in which a compromised phone becomes a proxy tool for remote attackers: they don’t just steal data, they can impersonate the user, conduct fraudulent transactions, or monitor every digital activity. Hence, users worldwide, not only in Poland or crypto-heavy regions, must remain vigilant: the architecture these threats use is platform-wide, not region-specific, and could easily be repurposed for broader global campaigns.

New Android Malware SeedSnatcher and FvncBot Found By Experts #Android #ClayRat #FvncBot

0 0 0 0
Post image

Malware Android FvncBot, SeedSnatcher e ClayRat rubano dati, mnemonici crypto e controllano i device abusando dell’accessibilità. Minacce 2025.

#Android #ClayRat #FvncBot #SeedSnatcher #trojanbancario
www.matricedigitale.it/2025/12/08/m...

0 0 0 0

Beware of ClayRat Android malware! It steals SMS messages, call logs, and photos, and spreads via fake apps. Stay safe: download apps only from trusted sources. #PotatoSecurity #AndroidMalware #ClayRat Link: thedailytechfeed.com/clayrat-andr...

0 0 0 0
Post image

Beware of ClayRat Android malware! It steals SMS messages, call logs, and photos, and spreads via fake apps. Stay safe: download apps only from trusted sources. #CyberSecurity #AndroidMalware #ClayRat Link: thedailytechfeed.com/clayrat-andr...

0 0 0 0
Preview
New Variant of ClayRat Android Spyware Seize Full Device Control Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

New variant of ClayRat Android spyware allows attackers to seize full device control - recording screen, stealing lock-screen credentials, and blocking removal.

Read: hackread.com/clayrat-andr...

#Android #Malware #CyberSecurity #Spyware #ClayRat

1 1 0 0
Preview
ClayRat: A New Breed of Android Spyware with Unprecedented Control A closer look at the sophisticated threat and its tactics. The mobile device landscape is under a constant barrage of new threats, with cybercriminals becoming increasingly adept at exploiting vulnerabilities in our everyday technology. One recently emerged player, ClayRat, represents a significant escalation in this regard, offering an unsettling glimpse into the potential for near-total […]
0 0 0 0
Post image

Beware of ClayRat malware disguising as popular apps like WhatsApp and Google Photos to steal your data. Stay safe by downloading apps only from official stores. #CyberSecurity #AndroidMalware #ClayRat Link: thedailytechfeed.com/clayrat-the-...

0 0 0 0
Preview
ClayRat Malware: New Android Threat Mimics Popular Apps to Steal Data A new type of malicious software, named ClayRat, is targeting Android users. It disguises itself as well-known apps. Think WhatsApp, TikTok, YouTube, and

ClayRat Malware: New Android Threat Mimics Popular Apps to Steal Data

#android #androidapps #ClayRat #malware #mobilesecurity

0 0 0 0
Post image

Beware of 'ClayRat' spyware disguising as popular apps like WhatsApp and TikTok. Protect your device by downloading apps only from official stores. #CyberSecurity #AndroidMalware #ClayRat Link: thedailytechfeed.com/emerging-and...

0 0 0 0
Preview
Ces fausses apps WhatsApp et YouTube infectées par le malware ClayRat Le malware ClayRat, se fait passer pour des applications très populaires comme WhatsApp, TikTok et YouTube pour piéger les utilisateurs d'Android.

🚨 Nouveau malware en circulation

ClayRat se fait passer pour des applis comme WhatsApp, TikTok ou YouTube pour infecter les smartphones Android 😱

Tous les détails ici 👇
www.it-connect.fr/android-le-m...

#CyberSécurité #Android #Malware #ClayRat

0 0 0 0

📰 Spyware Baru “ClayRat” Menyamar Jadi WhatsApp, TikTok, dan YouTube untuk Serang Pengguna Android

👉 Baca artikel lengkap di sini: ahmandonk.com/2025/10/10/clayrat-andro...

#android #clayrat #cybersecurity #google #play #protect #spyware #telegram #tiktok #whatsapp #youtube

1 0 0 0
Original post on securityaffairs.com

ClayRat campaign uses Telegram and phishing sites to distribute Android spyware ClayRat Android spyware targets Russian users via fake Telegram channels and phishing sites posing as popular apps li...

#Breaking #News #Cyber #Crime #Malware #ClayRat […]

[Original post on securityaffairs.com]

0 0 0 0
Preview
Fake TikTok and WhatsApp Apps Infect Android Devices with ClayRat Spyware Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

NEW: Watch out as new #ClayRat spyware is being distributed in fake Google Photos, YouTube, TikTok and WhatsApp Android apps, stealing SMS, call logs and photos, then spreading via contact SMS links.

Read more: hackread.com/fake-tiktok-...

#Cybersecurity #Spyware #Malware #AndroidSecurity #Russia

4 2 0 0
Post image

ClayRat e Velociraptor ridefiniscono le minacce cyber: spyware Android e tool forensics usati da Storm-2603 in attacchi ransomware globali.

#Android #CiscoTalos #ClayRat #Ransomware #spyware #Storm2603 #Velociraptor #Zimperium
www.matricedigitale.it/2025/10/09/c...

0 0 0 0
ASEC Blog publishes “Mobile Security & Malware Issue 2st Week of October, 2025” #### Tags: Android ClayRat malware ProSpy ToSpy

Mobile Security & Malware Issue 2st Week of October, 2025 ASEC Blog publishes “Mobile Security & Malware Issue 2st Week of October, 2025”

#Mobile #Public #Android #ClayRat #malware #ProSpy #ToSpy

Origin | Interest | Match

0 0 0 0
Preview
ClayRat Spyware Campaign Targets Android Users via Telegram and Fake WhatsApp, TikTok, YouTube Sites The ClayRat Android spyware campaign targets users via Telegram and phishing to steal data and self-propagate.

Full details: www.technadu.com/clayrat-spyw...

Full breakdown: www.technadu.com/clayrat-spyw...

#AndroidSecurity #Spyware #ClayRat #MobileThreats

0 0 0 0
Post image

New Android spyware ClayRat spreads via Telegram & fake WhatsApp/TikTok sites.

Steals SMS, calls, camera data & auto-spreads via contacts.

#AndroidSpyware #ClayRat #CyberSecurity #TechNadu

0 0 1 0
Post image

What's he doing?
His best!
#art #culture #clayrat

4 0 1 0