A new strain of Android malware called Cellik is a clear sign of where mobile threats are heading. It does the kind of surveillance that used to be reserved for expensive, government grade spyware, but it is sold as a monthly subscription that almost anyone can rent. What makes it especially worrying is how it spreads. Cybercriminals can wrap Cellik inside a copy of a real, popular app, so the malicious version looks and behaves like the app you actually wanted.
This article explains what Cellik is, what it can do to an infected phone, how it gets onto a device, the warning signs to watch for, and the practical steps you can take to protect yourself and your organization.
Cellik is an Android Remote Access Trojan, usually shortened to RAT. A RAT is malware that gives an attacker remote control over a device. Once it is installed, the operator can watch, listen, read, and act on the phone from anywhere in the world, often without the owner noticing anything at all.
Cellik was first documented in December 2025 after security researchers found it being advertised on cybercrime channels. Since then it has been covered by a range of security news outlets, including SecurityWeek, Dark Reading, and BleepingComputer. So while it is relatively new, it is a real and independently verified threat, not a rumor.
Cellik is sold as Malware as a Service, or MaaS. This is the same subscription model you see with legitimate software. The people who build the malware rent it out through a control panel, handle the back end infrastructure, and provide tutorials and support, while their customers point it at victims. The result is that even people with little technical skill can run a surveillance campaign.
Reporting on the malware puts the entry price at roughly a few hundred dollars a month, which tells you how cheap and accessible this kind of capability has become. That low cost is the whole point of the business model, and it is why threats like this are spreading.
Cellik is not the first tool of its kind. Researchers have tracked similar Android MaaS families such as HyperRat, PhantomOS, and Nebula. What sets Cellik apart is the breadth of what it can do for the price, and one feature in particular that we will come back to below: its ability to hide inside legitimate Play Store apps.
Once Cellik is running on a device, it gives the attacker a wide and unpleasant range of control. The capabilities below are the ones confirmed in the published research. Think of them less as a technical spec sheet and more as a list of everything you stand to lose.

Keylogging. Cellik can record what you type across the device. Anything you enter, including passwords, private messages, and search queries, can be captured.
Notification interception. The malware can read all of your notifications, both the live ones as they arrive and the earlier history. This is more dangerous than it sounds, because one time passcodes and two factor authentication codes usually arrive as notifications or text messages. If an attacker can read those, then a second factor that is supposed to protect your accounts stops protecting you.
Camera and microphone access. The operator can access the front and back cameras and the microphone, which allows remote photos, audio recording, and live listening.
Full file access. Cellik can browse your entire file system, download files off the device, upload new files onto it, delete data, and reach cloud storage folders that are linked to the phone. All of this is done over encrypted connections, which makes the activity harder to spot on the network.
A hidden browser for session hijacking. This is one of Cellik’s more insidious features. It runs an invisible web browser in the background that you never see on your screen. The attacker can use it to open websites, click links, and fill in forms, all while receiving a live stream of screenshots. Because your phone is already logged into your accounts, the attacker can use your saved sessions and cookies to get into those accounts, or quietly submit credentials on phishing pages. If you are tricked into entering a password or card number, the malware captures it.
Overlay and injection attacks. Cellik can draw fake screens on top of your real apps. A common version of this is a counterfeit login screen that appears over your banking or email app. You think you are logging into your bank, but you are actually handing your credentials straight to the attacker. Cellik includes a builder for creating these fake overlays for specific apps, and it can run several of them at once. That means it can be phishing your banking login and your email login at the same time, feeding both back to the attacker.
Beyond these confirmed features, the people selling Cellik advertise an expanding feature set in newer versions, including things like location tracking, cryptocurrency wallet theft, and other data collection. It is worth being a little skeptical of every claim a criminal seller makes, since marketing copy is often inflated. But the core capabilities above have been documented by researchers, and on their own they are more than enough to drain a bank account, take over online accounts, and expose a person’s private life.
Most of Cellik’s individual features can be found in other Android RATs. The reason it has drawn so much attention is how it is distributed.
Cellik’s control panel is integrated with the Google Play Store. Through that panel, an attacker can browse the Play Store catalogue, pick a legitimate and popular app, and with a single click generate a new malicious version of it. The tool wraps the Cellik payload inside the real app and repackages it as an installer file. The end product looks like the app you wanted, because it is built around the app you wanted, but it secretly installs the malware in the background.
This matters for two reasons.
First, it removes the technical skill that used to be required to disguise malware. In the past, repackaging an app took some effort and know how. Cellik turns it into a one click operation, which is why researchers describe it as lowering the barrier to entry for mobile spying.
Second, it undermines a habit that many people rely on for safety. A lot of us assume that if an app looks and works like the real thing, it is the real thing. Cellik is specifically designed to break that assumption. The sellers even claim their wrapping technique can slip past Google Play Protect by hiding inside trusted app packages. It is important to be precise here: Google has not confirmed that Cellik actually defeats Play Protect, and Play Protect does block a great deal of malware. But the practical takeaway for you as a user is simple. You cannot judge whether an app is safe just because it looks familiar, especially if it did not come from the official store.

The main route is sideloading, which means installing an app from somewhere other than the official Google Play Store, usually as a standalone APK file. Cellik’s repackaged apps are spread through channels like these:
Links in phishing emails and scam text messages, sometimes called smishing, that push you to download an app or an update
Fake or unofficial app stores and download sites
Websites offering free, cracked, or modified versions of paid apps and games
Fake update prompts that claim your phone or an app needs an urgent update
Direct messages or files sent by an attacker who is socially engineering you into installing something
The common thread is that a person is persuaded to install an app that came from outside the official store. Cellik does not magically appear on a locked down phone on its own. Someone has to be convinced to open the door. That is good news, because it means careful habits go a long way.
There is also a more targeted scenario worth naming. Because installing Cellik requires access to the device or the ability to trick the owner, this class of malware is sometimes used by people who have physical or personal access to a victim, for example in cases of stalking or domestic abuse. If you have reason to believe someone with access to your phone may have installed monitoring software, treat that as a serious situation and consider seeking help from a professional or a support organization rather than confronting it alone.
Cellik is built to stay hidden, so there is no single obvious red flag. It can hide its icon, run quietly in the background, and keep itself out of your recent apps list. That said, malware that is constantly streaming your screen, logging keys, and phoning home tends to leave traces. Watch for a combination of the following:
Faster than normal battery drain, or the phone feeling warm when you are not using it
A noticeable jump in mobile data usage that you cannot account for
The phone feeling sluggish, freezing, or restarting on its own
The screen lighting up, flickering, or showing brief flashes when you are not touching it
Apps you do not remember installing, or an app that seems to have no real purpose
A login screen or permission prompt that looks slightly off, or an app that unexpectedly asks for very broad permissions
Unexpected two factor codes arriving, or notifications that you have logged into an account you did not log into
Google Play Protect or your security software flagging an app
One honest caveat: a well built RAT is designed specifically to avoid these symptoms, so the absence of warning signs is not proof that a device is clean. If you have a concrete reason to be worried, act on it rather than waiting for symptoms to appear.
You do not need to be a security expert to do a basic self check. The following steps go through the settings that malware like Cellik depends on. Exact menu names vary a little between phone brands and Android versions, but the ideas are the same.
Review which apps have Accessibility access. Accessibility permissions are one of the most powerful things an app can hold on Android, because they allow an app to read the screen and act on your behalf. Malware relies heavily on them. Go into Settings, find Accessibility, and look at the list of apps that have it turned on. If anything there is unfamiliar or does not have a legitimate reason to need it, that is a serious red flag.
Review Device Admin apps. In Settings, look for Device admin apps or Device administrators, often under Security. Malware sometimes registers here to make itself harder to remove. Turn off anything you do not recognize.
Review apps with special permissions. Check which apps can display over other apps, which can read your notifications, and which have usage access. On most phones these live under Settings, Apps, then Special app access. Overlay and notification permissions are exactly what an overlay and interception attack needs.
Look through your full app list. In Settings, Apps, view all installed apps rather than just the ones showing on your home screen. Hidden or oddly named apps that you did not install deserve suspicion.
Run a Play Protect scan. Open the Google Play Store, tap your profile icon, choose Play Protect, and run a scan. Make sure Play Protect is turned on while you are there.
Check battery and data usage by app. In battery and data settings you can usually see which apps are consuming the most. An unfamiliar app near the top of either list is worth investigating.
Confirm that installing unknown apps is turned off. Look for the setting that allows installing unknown or third party apps and make sure it is disabled for your browsers and messaging apps. This is the switch that sideloaded malware needs.
Prevention is far easier than cleanup. These habits will keep you safe from Cellik and from the great majority of Android malware.
If you have real reason to believe Cellik or similar malware is on your device, move carefully and in this general order.
If you are a high risk individual, for example a journalist, an executive, or someone worried about a personal threat, consider engaging a professional for a proper forensic examination before you wipe the device, since a reset also destroys the evidence.
Cellik represents a broader shift in cybercrime: mobile phones are now a serious part of the attack surface, and they are often the least protected part. Employees carry corporate email, chat, files, and account access in their pockets, frequently on personal devices under a bring your own device arrangement. A single compromised phone can expose credentials, intercept multi factor codes, and give an attacker a foothold into systems that are otherwise well defended.
Defending against this is about layers rather than any single product. It generally includes clear mobile usage and app policies, mobile device management or mobile threat detection so that risky apps and compromised devices can be spotted, app vetting for anything that touches corporate data, ongoing security awareness training so that staff recognize smishing and fake app lures, and a tested incident response plan for when a device is compromised.
At X10 Technologies, we help organizations across the region strengthen their security posture, including the mobile devices that are so often overlooked.
Whether you need help evaluating your mobile and endpoint defenses, delivering security awareness training so your team can recognize threats like Cellik, or responding to a suspected compromise, our team is here to help.
Reach out to us to start a conversation about protecting your people and your data.