Mobile security researchers reported a newly identified commercial spyware toolkit dubbed ZeroDayRAT that provides operators broad, remote control of both Android and iOS devices and is being marketed to buyers via Telegram channels that include sales, customer support, and updates. Analysis attributed to iVerify describes a mass-market packaging of surveillance and info-stealing capabilities typically associated with higher-end commercial spyware, delivered through an operator-facing control panel intended to lower the technical barrier for use.
ZeroDayRAT infections are primarily driven by social engineering that tricks victims into installing a malicious mobile binary (e.g., APK on Android or an iOS payload), including smishing links, phishing emails, fake apps/app stores, and links shared through messaging platforms such as WhatsApp and Telegram. Once installed, the spyware can enable real-time monitoring and data theft, including access to device and SIM details, location tracking, notification/SMS previews, and enumeration of accounts registered on the device—capabilities that can support account takeover (including MFA bypass via SMS visibility), targeted social engineering, and theft of banking/cryptocurrency-related data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Media reports published on February 10, 2026 disclosed iVerify's findings that ZeroDayRAT was being openly sold on Telegram with a web control panel and developer support, lowering the barrier to entry for mobile surveillance and account takeover operations. Reporting highlighted delivery through smishing, phishing, fake apps, and malicious links, as well as risks such as MFA bypass and executive targeting.
In February 2026, iVerify discovered and analyzed ZeroDayRAT, a commercial spyware platform targeting Android and iOS devices. The research found it offered full remote control, surveillance, credential theft, banking theft, and crypto theft features through operator-managed infrastructure.
iVerify assessed that the commercial mobile spyware toolkit ZeroDayRAT was first distributed and marketed via Telegram beginning on February 2, 2026. The operation included sales, support, and update channels for buyers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
vulnu.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.