A campaign has infected over 11,000 Android devices with a new variant of the PlayPraetor remote access trojan (RAT), identified by cybersecurity experts from Cleafy. The malware spreads through deceptive Google Play Store pages promoted via Meta Ads and SMS campaigns. Once installed, PlayPraetor can log keystrokes, steal credentials, and monitor the clipboard. Researchers have identified at least five distinct variants of PlayPraetor, including "Phantom" and "Phish."