Skip to main content
Mallory
Back to intelligence
remote-access-implantphishing-campaign-intelligencecredential-stealer-activitycybercrime-service-ecosystem

ZeroDayRAT Commercial Mobile Spyware Sold on Telegram

Updated 3mo agoFirst seen Feb 10, 20264 sources

Mobile security researchers reported a newly identified commercial spyware toolkit dubbed ZeroDayRAT that provides operators broad, remote control of both Android and iOS devices and is being marketed to buyers via Telegram channels that include sales, customer support, and updates. Analysis attributed to iVerify describes a mass-market packaging of surveillance and info-stealing capabilities typically associated with higher-end commercial spyware, delivered through an operator-facing control panel intended to lower the technical barrier for use.

ZeroDayRAT infections are primarily driven by social engineering that tricks victims into installing a malicious mobile binary (e.g., APK on Android or an iOS payload), including smishing links, phishing emails, fake apps/app stores, and links shared through messaging platforms such as WhatsApp and Telegram. Once installed, the spyware can enable real-time monitoring and data theft, including access to device and SIM details, location tracking, notification/SMS previews, and enumeration of accounts registered on the device—capabilities that can support account takeover (including MFA bypass via SMS visibility), targeted social engineering, and theft of banking/cryptocurrency-related data.

Share:
ZeroDayRAT Commercial Mobile Spyware Sold on Telegram
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 10, 20264mo ago

Public reporting reveals ZeroDayRAT's mass-market spyware model

Media reports published on February 10, 2026 disclosed iVerify's findings that ZeroDayRAT was being openly sold on Telegram with a web control panel and developer support, lowering the barrier to entry for mobile surveillance and account takeover operations. Reporting highlighted delivery through smishing, phishing, fake apps, and malicious links, as well as risks such as MFA bypass and executive targeting.

iVerify identifies and analyzes ZeroDayRAT spyware

In February 2026, iVerify discovered and analyzed ZeroDayRAT, a commercial spyware platform targeting Android and iOS devices. The research found it offered full remote control, surveillance, credential theft, banking theft, and crypto theft features through operator-managed infrastructure.

Feb 2, 20264mo ago

ZeroDayRAT begins distribution on Telegram

iVerify assessed that the commercial mobile spyware toolkit ZeroDayRAT was first distributed and marketed via Telegram beginning on February 2, 2026. The operation included sales, support, and update channels for buyers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.