ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live Cam/Mic/Screen, Crypto Clipboard Hijacking, Banking Overlays, SMS OTP Bypass — Threadlinqs Intelligence
As of 2026-05-30, ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live Cam/Mic/Screen, Crypto Clipboard Hijacking, Banking Overlays, SMS OTP Bypass is a high-severity malware threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0116 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: N/A · FINANCIAL
ZeroDayRAT is a new commercial mobile spyware platform sold openly on Telegram, first observed February 2, 2026. Cross-platform: Android 5-16 and iOS up to 26 (including iPhone 17 Pro). Browser-based
ZeroDayRAT is a fully operational commercial mobile spyware platform identified by iVerify in February 2026, sold openly through Telegram with dedicated channels for sales, customer support, and regular updates. The platform provides a single buyer with complete surveillance and financial theft capabilities over Android and iOS devices, operated entirely through a browser-based dashboard requiring no technical expertise.
**PLATFORM ARCHITECTURE:**
The developer maintains a Telegram-based distribution model with dedicated channels for sales, support, and updates. Buyers receive access to a browser-based C2 panel (operator dashboard) that provides real-time device management. The dashboard displays infected devices with country indicators (iVerify screenshots show devices in India and the US), device metadata, and full control interfaces organized by function.
**DELIVERY MECHANISMS:**
- **Smishing:** Primary vector — text messages with links to malicious APK (Android) or iOS payload downloads disguised as legitimate apps
- **Phishing emails:** Secondary vector for enterprise targeting
- **Fake app stores:** Mimicking legitimate app distribution
- **Messaging lures:** Links shared via WhatsApp and Telegram chats creating urgency
**CAPABILITY MODULES (from iVerify analysis):**
1. **Device Overview & User Profiling:** Device model, OS version, battery, country, lock status, SIM/carrier info, dual SIM phone numbers, app usage broken down by time, live activity timeline, recent SMS preview — all on a single screen. Enough to profile the target: who they talk to, what apps they use, when active, what network.
2. **Location Tracking:** GPS coordinates plotted on embedded Google Maps with full location history. Real-time and historical tracking. iVerify screenshot shows tracking in Bengaluru, India.
3. **Notification Capture:** All app notifications intercepted: app name, title, content, timestamp. WhatsApp messages, Instagram, missed calls, Telegram, YouTube, system events. Passive visibility into everything on the phone without opening any app.
4. **Account Enumeration:** Every account registered on the device listed: Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, Flipkart, PhonePe, Paytm, Spotify, and more with associated usernames/emails. Complete account takeover and social engineering intelligence.
5. **SMS Access & OTP Interception:** Full inbox search, ability to SEND messages from the victim's number, visibility into incoming OTP codes from banks/platforms. SMS-based 2FA is completely bypassed.
6. **Live Surveillance:** Real-time camera streaming (front and back), screen recording, microphone feed. Combined with GPS = watch, listen to, and locate target simultaneously. All from a single panel tab.
7. **Keylogging:** Every input captured with app context and millisecond timestamps — biometric unlocks, gestures, keystrokes, app launches. Live screen preview alongside keylogger output.
8. **Crypto Stealer:** Detects wallet apps (MetaMask, Trust Wallet, Binance, Coinbase), logs wallet IDs and balances, performs clipboard address injection — silently replaces copied wallet addresses with attacker's address to redirect transfers.
9. **Banking Stealer:** Overlay attacks targeting banking apps, UPI platforms (PhonePe, Google Pay), Apple Pay, PayPal. Credential capture through fake overlays.
**MARKET POSITIONING — COMMODITY SPYWARE:**
ZeroDayRAT represents the COMMODITIZATION of mobile surveillance. Capabilities that previously required nation-state investment (NSO Pegasus ~$8M per deployment, Cytrox Predator ~$6M) or bespoke exploit development are now available to ANY buyer on Telegram with no technical knowledge required. The ready-to-run model with customer support transforms advanced surveillance from a state capability to a consumer product.
**COMPARISON TO KNOWN SPYWARE:**
- **NSO Pegasus:** Zero-click, zero-day exploits, government-only sales, ~$8M/deployment. ZeroDayRAT is user-interaction-required, sold
Target sectors: Financial Services, Cryptocurrency, Banking, Technology, Individuals
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1430, T1517, T1412, T1513, T1512, T1429, T1417.001, T1417.002, T1510