# ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live Cam/Mic/Screen, Crypto Clipboard Hijacking, Banking Overlays, SMS OTP Bypass

> ZeroDayRAT is a new commercial mobile spyware platform sold openly on Telegram, first observed February 2, 2026. Cross-platform: Android 5-16 and iOS up to 26 (including iPhone 17 Pro). Browser-based C2 panel provides full remote device control without technical expertise. Capabilities span real-time surveillance (live camera/mic/screen), financial theft (crypto clipboard swapping, banking overlays), and comprehensive data collection (GPS, SMS/OTP, notifications, keylogging, account enumeration). Represents the commoditization of capabilities previously requiring nation-state investment.

- **Published:** 2026-02-16T12:39:16Z
- **Last reviewed:** 2026-02-16T12:39:16Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0116
- **ID:** TL-2026-0116
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ZeroDayRAT is a fully operational commercial mobile spyware platform identified by iVerify in February 2026, sold openly through Telegram with dedicated channels for sales, customer support, and regular updates. The platform provides a single buyer with complete surveillance and financial theft capabilities over Android and iOS devices, operated entirely through a browser-based dashboard requiring no technical expertise.

**PLATFORM ARCHITECTURE:**
The developer maintains a Telegram-based distribution model with dedicated channels for sales, support, and updates. Buyers receive access to a browser-based C2 panel (operator dashboard) that provides real-time device management. The dashboard displays infected devices with country indicators (iVerify screenshots show devices in India and the US), device metadata, and full control interfaces organized by function.

**DELIVERY MECHANISMS:**
- **Smishing:** Primary vector — text messages with links to malicious APK (Android) or iOS payload downloads disguised as legitimate apps
- **Phishing emails:** Secondary vector for enterprise targeting
- **Fake app stores:** Mimicking legitimate app distribution
- **Messaging lures:** Links shared via WhatsApp and Telegram chats creating urgency

**CAPABILITY MODULES (from iVerify analysis):**

1. **Device Overview & User Profiling:** Device model, OS version, battery, country, lock status, SIM/carrier info, dual SIM phone numbers, app usage broken down by time, live activity timeline, recent SMS preview — all on a single screen. Enough to profile the target: who they talk to, what apps they use, when active, what network.

2. **Location Tracking:** GPS coordinates plotted on embedded Google Maps with full location history. Real-time and historical tracking. iVerify screenshot shows tracking in Bengaluru, India.

3. **Notification Capture:** All app notifications intercepted: app name, title, content, timestamp. WhatsApp messages, Instagram, missed calls, Telegram, YouTube, system events. Passive visibility into everything on the phone without opening any app.

4. **Account Enumeration:** Every account registered on the device listed: Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, Flipkart, PhonePe, Paytm, Spotify, and more with associated usernames/emails. Complete account takeover and social engineering intelligence.

5. **SMS Access & OTP Interception:** Full inbox search, ability to SEND messages from the victim's number, visibility into incoming OTP codes from banks/platforms. SMS-based 2FA is completely bypassed.

6. **Live Surveillance:** Real-time camera streaming (front and back), screen recording, microphone feed. Combined with GPS = watch, listen to, and locate target simultaneously. All from a single panel tab.

7. **Keylogging:** Every input captured with app context and millisecond timestamps — biometric unlocks, gestures, keystrokes, app launches. Live screen preview alongside keylogger output.

8. **Crypto Stealer:** Detects wallet apps (MetaMask, Trust Wallet, Binance, Coinbase), logs wallet IDs and balances, performs clipboard address injection — silently replaces copied wallet addresses with attacker's address to redirect transfers.

9. **Banking Stealer:** Overlay attacks targeting banking apps, UPI platforms (PhonePe, Google Pay), Apple Pay, PayPal. Credential capture through fake overlays.

**MARKET POSITIONING — COMMODITY SPYWARE:**
ZeroDayRAT represents the COMMODITIZATION of mobile surveillance. Capabilities that previously required nation-state investment (NSO Pegasus ~$8M per deployment, Cytrox Predator ~$6M) or bespoke exploit development are now available to ANY buyer on Telegram with no technical knowledge required. The ready-to-run model with customer support transforms advanced surveillance from a state capability to a consumer product.

**COMPARISON TO KNOWN SPYWARE:**
- **NSO Pegasus:** Zero-click, zero-day exploits, government-only sales, ~$8M/deployment. ZeroDayRAT is user-interaction-required, sold to anyone, fraction of cost.
- **Cytrox Predator:** Single-click exploits, government sales. Similar capability level to ZeroDayRAT but with exploit-based delivery.
- **RCS Lab Hermit:** Government-grade, ISP-assisted delivery. ZeroDayRAT uses social engineering delivery instead.
- **CapraRAT (APT36, TL-0106):** Nation-state Android RAT. ZeroDayRAT provides similar capabilities but commercially available to non-state actors.

The key distinction: ZeroDayRAT democratizes surveillance. It doesn't use zero-day exploits — it relies on social engineering for delivery. This makes it less technically sophisticated but MORE accessible. The barrier to entry is Telegram access and payment, not exploit development capability.

## MITRE ATT&CK

- T1660 Phishing
- T1430 Location Tracking
- T1517 Access Notifications
- T1636.004 SMS Messages
- T1513 Screen Capture
- T1512 Video Capture
- T1429 Audio Capture
- T1417.001 Input Capture: Keylogging
- T1417.002 Input Capture: GUI Input Capture
- T1641.001 Transmitted Data Manipulation
- T1655.001 Masquerading: Match Legitimate Name or Location
- T1541 Foreground Persistence
- T1481 Web Service
- T1646 Exfiltration Over C2 Channel
- T1426 System Information Discovery
- T1636.003 Protected User Data: Contact List
- T1636.002 Protected User Data: Call Log
- T1636.001 Protected User Data: Calendar Entries
- T1418 Software Discovery
- T1628.001 Suppress Application Icon
- T1657 Financial Theft
- T1635 Steal Application Access Token
- T1398 Boot or Logon Initialization Scripts

## Sources

- [iVerify — Breaking Down ZeroDayRAT: New Spyware Targeting Android and iOS](https://iverify.io/blog/breaking-down-zerodayrat---new-spyware-targeting-android-and-ios)
- [Cyber Security News — New ZeroDayRAT Attacking Android and iOS](https://cybersecuritynews.com/new-zerodayrat-attacking-android-and-ios/)
- [MITRE ATT&CK Mobile Matrix](https://attack.mitre.org/matrices/mobile/)
- [Google TAG — Commercial Surveillance Vendors](https://blog.google/threat-analysis-group/)
- [Citizen Lab — Targeted Threats Research](https://citizenlab.ca/category/research/targeted-threats/)
- [iVerify — Mobile Threat Detection Platform](https://iverify.io/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0116
