ZeroDayRAT Mobile Spyware Sold on Telegram Targets Android and iOS
Researchers disclosed a new mobile spyware platform dubbed ZeroDayRAT that is being openly advertised and sold via Telegram channels, including sales, support, and update streams. iVerify reported first observing activity in early February 2026 and assessed the tool is positioned as a “ready-to-run” cross-platform spyware kit supporting Android 5–16 and iOS up to 26, with a browser-accessible (and in some cases self-hosted) operator panel intended to lower the technical barrier for buyers.
ZeroDayRAT’s capabilities include real-time surveillance and data theft: GPS tracking with location history (including Google Maps plotting), notification capture, SMS interception (including OTP codes used for 2FA), keylogging, screen recording, and live camera/microphone access. The operator panel also enumerates accounts registered on the device (e.g., Google, WhatsApp, Instagram, Telegram, Amazon and regional payment apps), enabling victim profiling and potential account takeover. Distribution is assessed to rely primarily on social engineering—particularly smishing links leading to fake download pages—along with phishing, fake app stores, and malicious links shared via messaging apps, resulting in installation of an Android APK or an iOS payload.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Researchers disclose ZeroDayRAT mobile spyware platform
On 2026-02-16, reporting by iVerify and subsequent coverage disclosed ZeroDayRAT as a cross-platform Android and iOS spyware platform capable of data theft and real-time surveillance. The disclosure detailed features such as SMS/OTP capture, GPS tracking, camera and microphone access, screen recording, banking overlays, and crypto theft functions, along with delivery via smishing, phishing, and fake app marketplaces.
ZeroDayRAT activity first observed and marketed on Telegram
Researchers said the ZeroDayRAT mobile spyware platform was first seen on 2026-02-02 being advertised openly on Telegram. The commercial offering included a self-hosted control panel and malware builder aimed at lower-skill operators.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


