Threat reportMalwareTL-2026-0116
ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live Cam/Mic/Screen, Crypto Clipboard Hijacking, Banking Overlays, SMS OTP Bypass
ZeroDayRAT Commercial Mobile Spyware (TL-2026-0116) is a high-severity malware campaign, first published 2026-02-16. It has no confirmed attribution, maps to 23 MITRE ATT&CK techniques (T1398, T1417.001, T1417.002), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-0116
- Threat ID
- TL-2026-0116
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- Financial Services, Cryptocurrency, Banking, Technology, Individuals
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in ZeroDayRAT Commercial Mobile Spyware
Malware and tooling: ZeroDayRAT
How ZeroDayRAT Commercial Mobile Spyware works
ZeroDayRAT is a new commercial mobile spyware platform sold openly on Telegram, first observed February 2, 2026. Cross-platform: Android 5-16 and iOS up to 26 (including iPhone 17 Pro). Browser-based C2 panel provides full remote device control without technical expertise. Capabilities span real-time surveillance (live camera/mic/screen), financial theft (crypto clipboard swapping, banking overlays), and comprehensive data collection (GPS, SMS/OTP, notifications, keylogging, account enumeration). Represents the commoditization of capabilities previously requiring nation-state investment.
ZeroDayRAT is a fully operational commercial mobile spyware platform identified by iVerify in February 2026, sold openly through Telegram with dedicated channels for sales, customer support, and regular updates. The platform provides a single buyer with complete surveillance and financial theft capabilities over Android and iOS devices, operated entirely through a browser-based dashboard requiring no technical expertise.
**PLATFORM ARCHITECTURE:** The developer maintains a Telegram-based distribution model with dedicated channels for sales, support, and updates. Buyers receive access to a browser-based C2 panel (operator dashboard) that provides real-time device management. The dashboard displays infected devices with country indicators (iVerify screenshots show devices in India and the US), device metadata, and full control interfaces organized by function.
**DELIVERY MECHANISMS:** - **Smishing:** Primary vector — text messages with links to malicious APK (Android) or iOS payload downloads disguised as legitimate apps - **Phishing emails:** Secondary vector for enterprise targeting - **Fake app stores:** Mimicking legitimate app distribution - **Messaging lures:** Links shared via WhatsApp and Telegram chats creating urgency
**CAPABILITY MODULES (from iVerify analysis):**
1. **Device Overview & User Profiling:** Device model, OS version, battery, country, lock status, SIM/carrier info, dual SIM phone numbers, app usage broken down by time, live activity timeline, recent SMS preview — all on a single screen. Enough to profile the target: who they talk to, what apps they use, when active, what network.
2. **Location Tracking:** GPS coordinates plotted on embedded Google Maps with full location history. Real-time and historical tracking. iVerify screenshot shows tracking in Bengaluru, India.
3. **Notification Capture:** All app notifications intercepted: app name, title, content, timestamp. WhatsApp messages, Instagram, missed calls, Telegram, YouTube, system events. Passive visibility into everything on the phone without opening any app.
4. **Account Enumeration:** Every account registered on the device listed: Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, Flipkart, PhonePe, Paytm, Spotify, and more with associated usernames/emails. Complete account takeover and social engineering intelligence.
5. **SMS Access & OTP Interception:** Full inbox search, ability to SEND messages from the victim's number, visibility into incoming OTP codes from banks/platforms. SMS-based 2FA is completely bypassed.
6. **Live Surveillance:** Real-time camera streaming (front and back), screen recording, microphone feed. Combined with GPS = watch, listen to, and locate target simultaneously. All from a single panel tab.
7. **Keylogging:** Every input captured with app context and millisecond timestamps — biometric unlocks, gestures, keystrokes, app launches. Live screen preview alongside keylogger output.
8. **Crypto Stealer:** Detects wallet apps (MetaMask, Trust Wallet, Binance, Coinbase), logs wallet IDs and balances, performs clipboard address injection — silently replaces copied wallet addresses with attacker's address to redirect transfers.
9. **Banking Stealer:** Overlay attacks targeting banking apps, UPI platforms (PhonePe, Google Pay), Apple Pay, PayPal. Credential capture through fake overlays.
**MARKET POSITIONING — COMMODITY SPYWARE:** ZeroDayRAT represents the COMMODITIZATION of mobile surveillance. Capabilities that previously required nation-state investment (NSO Pegasus ~$8M per deployment, Cytrox Predator ~$6M) or bespoke exploit development are now available to ANY buyer on Telegram with no technical knowledge required. The ready-to-run model with customer support transforms advanced surveillance from a state capability to a consumer product.
**COMPARISON TO KNOWN SPYWARE:** - **NSO Pegasus:** Zero-click, zero-day exploits, government-only sales, ~$8M/deployment. ZeroDayRAT is user-interaction-required, sold to anyone, fraction of cost. - **Cytrox Predator:** Single-click exploits, government sales. Similar capability level to ZeroDayRAT but with exploit-based delivery. - **RCS Lab Hermit:** Government-grade, ISP-assisted delivery. ZeroDayRAT uses social engineering delivery instead. - **CapraRAT (APT36, TL-0106):** Nation-state Android RAT. ZeroDayRAT provides similar capabilities but commercially available to non-state actors.
The key distinction: ZeroDayRAT democratizes surveillance. It doesn't use zero-day exploits — it relies on social engineering for delivery. This makes it less technically sophisticated but MORE accessible. The barrier to entry is Telegram access and payment, not exploit development capability.
MITRE ATT&CK techniques used in TL-2026-0116
Persistence
T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence
Collection
T1417.001 Input Capture: Keylogging; T1429 Audio Capture; T1430 Location Tracking; T1512 Video Capture; T1513 Screen Capture; T1517 Access Notifications; T1636.001 Protected User Data: Calendar Entries; T1636.002 Protected User Data: Call Log; T1636.003 Protected User Data: Contact List; T1636.004 SMS Messages
Credential Access
T1417.002 Input Capture: GUI Input Capture; T1635 Steal Application Access Token
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Command and Control
Defense Evasion
T1628.001 Suppress Application Icon; T1655.001 Masquerading: Match Legitimate Name or Location
Impact
T1641.001 Transmitted Data Manipulation
Exfiltration
T1646 Exfiltration Over C2 Channel
impact
Initial Access
Remediation for ZeroDayRAT Commercial Mobile Spyware
Patches
- N/A — ZeroDayRAT is not a vulnerability, it is a commercial spyware tool delivered via social engineering
Immediate actions
- INSTALL ONLY FROM OFFICIAL STORES: Never sideload APKs or install from links in text messages, emails, or messaging apps
- VERIFY LINKS: Do not tap links in unsolicited SMS/WhatsApp/Telegram messages, especially those creating urgency
- CHECK PERMISSIONS: Review app permissions regularly — camera, microphone, accessibility services, SMS access should only be granted to trusted apps
- UPGRADE MFA: Replace SMS-based 2FA with authenticator apps (TOTP) or hardware keys (FIDO2) — ZeroDayRAT intercepts SMS OTPs
- VERIFY CRYPTO ADDRESSES: Always manually verify cryptocurrency recipient addresses before confirming transfers — clipboard hijacking silently replaces addresses
Workarounds
- Limit sideloading to strictly necessary cases
- Use app-based TOTP instead of SMS for 2FA
- Enable Play Protect (Android) or Lockdown Mode (iOS)
- Regular device scans with mobile security tools
Longer-term hardening
- DEPLOY MOBILE EDR: Use mobile threat detection solutions (iVerify, Lookout, Zimperium) to detect spyware indicators on managed and BYOD devices
- DISABLE SIDELOADING: Enterprise MDM should prevent sideloading on managed devices (Android: disable 'Install from unknown sources')
- LOCKDOWN MODE: Apple iOS Lockdown Mode blocks many attack vectors used by commercial spyware
- MOBILE THREAT MONITORING: Implement organizational process for triaging suspected spyware — rapid reporting limits damage
- BEHAVIORAL INDICATORS: Monitor for battery drain, unknown accessibility services, unexpected permission prompts, unusual data usage
Timeline of ZeroDayRAT Commercial Mobile Spyware
- Context: NSO Pegasus, Cytrox Predator, RCS Lab Hermit established the commercial spyware market at the government/enterprise tier ($5-50M). ZeroDayRAT represents the COMMODITY tier — same capability class, fraction of cost, no buyer vetting, Telegram distribution.
- Context: The commercial mobile spyware market continues expanding. Google TAG, Citizen Lab, and Amnesty Tech have documented 30+ commercial surveillance vendors. ZeroDayRAT represents the commodity tier — no zero-day exploits, social engineering delivery, Telegram sales model.
- ZeroDayRAT first observed active on Telegram with dedicated sales, support, and update channels. Commercial mobile spyware platform available for purchase with browser-based C2 panel. Source: iVerify.
- iVerify screenshots show infected devices in India (Bengaluru GPS tracking) and the United States. Banking module targets Indian UPI platforms (PhonePe, Paytm, Flipkart) alongside global platforms (PayPal, Apple Pay). South Asian financial ecosystem is primary target.
- ZeroDayRAT developer maintains active Telegram channels with regular updates, indicating ongoing development and feature expansion. Cross-platform support (Android 5-16, iOS up to 26 including iPhone 17 Pro) suggests active testing against latest devices.
- Cyber Security News publishes coverage: 'New ZeroDayRAT Attacking Android and iOS For Real-Time Surveillance and Data Theft.' Amplifies iVerify findings to broader security community. Source: https://cybersecuritynews.com/new-zerodayrat-attacking-android-and-ios/
- iVerify publishes technical breakdown of ZeroDayRAT: 'Breaking Down ZeroDayRAT — New Spyware Targeting Android and iOS.' Includes C2 dashboard screenshots showing infected devices in India and US. Source: https://iverify.io/blog/breaking-down-zerodayrat---new-spyware-targeting-android-and-ios
- As of 2026-05-29, ZeroDayRAT remains an active, undisrupted commercial mobile spyware platform still sold openly on Telegram (~$2,000), per iVerify, Hacker News, SecurityWeek and Dark Reading. No CVE applies (smishing/social-engineering delivery, not exploits), and no takedown, arrests, or successor exist; its decentralized self-hosted-operator model makes disruption difficult.
Sources cited for ZeroDayRAT Commercial Mobile Spyware
Detection coverage for TL-2026-0116
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0116 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.