Threxar has identified a previously undocumented mobile spyware framework being deployed against journalists, human rights researchers, and NGO staff across Southeast Asia. We are tracking this toolset as "ClearTrack."

Delivery Method

ClearTrack is delivered via two observed vectors:

1. Social engineering via messaging applications - targets receive links to what appear to be shared documents or news articles, which instead redirect to a drive-by installation page

2. Physical device access - a "one-click install" version exists that requires brief physical access to an unlocked device

Capabilities

Analysed samples demonstrate the following capabilities:

  • SMS/call log interception
  • Live microphone access (triggered by keyword detection in ambient audio)
  • Location tracking with configurable reporting intervals
  • Camera access with silent capture mode
  • Encrypted exfiltration to a hardcoded C2 endpoint

Attribution

Attribution remains low-confidence. Tooling artefacts suggest a development environment using Simplified Chinese locales, though this may be deliberate misdirection.