Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitycybercrime-service-ecosystemphishing-campaign-intelligenceinitial-access-method

ZeroDayRAT Mobile Spyware Sold on Telegram Targets Android and iOS

Updated 3mo agoFirst seen Feb 16, 20262 sources

Researchers disclosed a new mobile spyware platform dubbed ZeroDayRAT that is being openly advertised and sold via Telegram channels, including sales, support, and update streams. iVerify reported first observing activity in early February 2026 and assessed the tool is positioned as a “ready-to-run” cross-platform spyware kit supporting Android 5–16 and iOS up to 26, with a browser-accessible (and in some cases self-hosted) operator panel intended to lower the technical barrier for buyers.

ZeroDayRAT’s capabilities include real-time surveillance and data theft: GPS tracking with location history (including Google Maps plotting), notification capture, SMS interception (including OTP codes used for 2FA), keylogging, screen recording, and live camera/microphone access. The operator panel also enumerates accounts registered on the device (e.g., Google, WhatsApp, Instagram, Telegram, Amazon and regional payment apps), enabling victim profiling and potential account takeover. Distribution is assessed to rely primarily on social engineering—particularly smishing links leading to fake download pages—along with phishing, fake app stores, and malicious links shared via messaging apps, resulting in installation of an Android APK or an iOS payload.

Share:
ZeroDayRAT Mobile Spyware Sold on Telegram Targets Android and iOS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Feb 16, 20264mo ago

Researchers disclose ZeroDayRAT mobile spyware platform

On 2026-02-16, reporting by iVerify and subsequent coverage disclosed ZeroDayRAT as a cross-platform Android and iOS spyware platform capable of data theft and real-time surveillance. The disclosure detailed features such as SMS/OTP capture, GPS tracking, camera and microphone access, screen recording, banking overlays, and crypto theft functions, along with delivery via smishing, phishing, and fake app marketplaces.

Feb 2, 20265mo ago

ZeroDayRAT activity first observed and marketed on Telegram

Researchers said the ZeroDayRAT mobile spyware platform was first seen on 2026-02-02 being advertised openly on Telegram. The commercial offering included a self-hosted control panel and malware builder aimed at lower-skill operators.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

66 LINKEDOpen in app
Affected products
22 linked
AndroidTelegramWhatsappAndroidIosIosPhonepeMediafireFacebookTeamviewerGoogle DriveSpotifyInstagramAnydeskDiscordGetappsPaypalGithubGoogle DriveMetamaskGoogleChrome
Organizations
26 linked
iVerifySpotifyPhonepeHugging FacePaytmCTM360Amazon Web ServicesDiscordBinanceMediafireXiaomiMeta PlatformsCoinbaseApplePayPalGitHubDeutsche BankAnyDesk Software GmbHTelegramGroup-IBTeamviewerMetamaskTrust WalletGoogleGoogle PayFlipkart
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ZeroDayRAT Mobile Spyware Sold on Telegram Targets Android and iOS | Mallory