logo

ZeroDayRAT spyware grants attackers total access to mobile devices

ID: e5b03d5b-32f0-5579-9d1f-8fe39aca76ad

STIX ID: report--e5b03d5b-32f0-5579-9d1f-8fe39aca76ad

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ZeroDayRAT is a commercially sold cross-platform mobile spyware toolkit that provides operators full remote access to Android and iOS devices — including live camera/microphone streaming, keylogging, screen recording, GPS tracking, notification/oauth/account enumeration, and modules for stealing crypto and banking credentials. First observed in February 2026 and analyzed by iVerify, the tool is distributed via Telegram, offers an easy web-based control panel for buyers, and is spread through smishing, phishing, fake apps, and malicious links, posing a high risk to individual users and organizations handling sensitive accounts or financial assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.