Back to Blog
Spyware Analysis

The Evolution of Commercial Spyware: ZeroDayRAT and the Persistent Pegasus Threat

Analysis of the latest commercial spyware trends, including the emergence of ZeroDayRAT and new Pegasus infections targeting European lawmakers and activists.

The Evolution of Commercial Spyware: ZeroDayRAT and the Persistent Pegasus Threat

The Democratization of Mobile Surveillance: The Rise of ZeroDayRAT

The landscape of mobile surveillance is undergoing a radical shift as high-tier capabilities, once reserved for nation-state actors, are now being commoditized for a broader market. In February 2026, cybersecurity researchers identified a new commercial spyware platform dubbed ZeroDayRAT, which is being aggressively marketed via Telegram channels. Unlike the clandestine operations of the NSO Group, ZeroDayRAT represents a "spyware-as-a-service" model that provides buyers with a centralized C2 dashboard for real-time monitoring of both Android and iOS devices according to New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft.

ZeroDayRAT is technically significant because it bridges the gap between traditional mobile malware and professional-grade cellphone spyware. It supports Android versions up to 16 and iOS versions up to 26, offering features that include live audio streaming, front-camera activation, and direct financial theft capabilities. This democratization of surveillance tools means that corporate espionage and targeted harassment no longer require the multi-million dollar budgets associated with Pegasus. For professionals, this necessitates a shift toward encrypted phones that utilize hardened kernels to prevent the initial execution of such remote access trojans (RATs).

Pegasus Persistence and the Zero-Click Arms Race

Despite international sanctions and blacklisting, NSO Group’s Pegasus remains the gold standard for zero-click exploitation. A zero-click attack is a sophisticated intrusion method that requires no interaction from the victim—such as clicking a link or opening an attachment—to fully compromise a device. Recent reports from Citizen Lab have confirmed that Pegasus continues to be used against high-profile targets, including European Parliament members who were actively investigating the abuse of the software itself as noted in Pegasus spyware found on phone of MEP investigating its abuse.

The technical resilience of Pegasus lies in its use of novel exploits that bypass standard memory protections in modern smartphones. While Apple and Google have introduced features like Lockdown Mode and Advanced Data Protection, commercial vendors are constantly identifying new vulnerabilities in core system components like iMessage and the Chrome browser. For those seeking a Pegasus spyware alternative for defensive purposes, the focus has shifted toward hardware surveillance countermeasures, where physical switches are used to disconnect microphones and cameras, providing a layer of security that software-based encrypted communications cannot guarantee alone.

Mobile Forensics and the Threat of Physical Extraction

While remote exploitation dominates the headlines, the threat of physical cellular interception and data extraction remains a critical concern for activists and legal professionals. In February 2026, forensic analysis revealed that Cellebrite’s extraction tools were used on the device of a Kenyan pro-democracy activist while in police custody. Mobile forensics refers to the scientific recovery of digital evidence from a mobile device under legally audited conditions, but in this instance, the tools were used to bypass password protections entirely, leaving the device vulnerable and unlocked upon its return to the owner according to Citizen Lab finds Cellebrite tool used.

This case highlights a growing trend where commercial vendors provide the means for state actors to bypass encrypted communications by targeting the device's physical storage. When a device is in a "Before First Unlock" (BFU) state, most data is encrypted; however, forensic tools often exploit vulnerabilities in the bootloader or Secure Enclave to move the device into an "After First Unlock" (AFU) state where data exfiltration becomes trivial. This underscores the importance of using spyware for phones detection tools and maintaining strict physical security protocols for sensitive hardware.

The Encryption Paradox: Apple’s RCS E2EE vs. On-Device Compromise

In a significant move for mobile privacy, Apple has begun testing end-to-end encryption (E2EE) for Rich Communications Services (RCS) in the iOS 26.4 developer beta. This feature ensures that messages sent between Apple devices are encrypted in transit, preventing cellular interception by mobile carriers or third-party interceptors as detailed in Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta. However, the rise of commercial spyware creates an "encryption paradox": while the data is secure during transmission, it is completely exposed once it reaches the endpoint if the device itself is compromised.

Spyware like Pegasus and ZeroDayRAT does not attempt to break the encryption protocols of apps like Signal or WhatsApp. Instead, they use keyloggers and screen-scraping techniques to capture the data before it is encrypted or after it is decrypted for the user. This reality makes the case for specialized hardware-modified phones that run minimal, audited operating systems designed to reduce the attack surface. As commercial vendors continue to exploit the complexity of modern mobile OSs, the only viable defense is a multi-layered approach combining robust E2EE with hardware-level security controls.

Key Takeaway

The current state of mobile security is defined by a dual threat: the continued use of elite zero-click tools like Pegasus by state actors and the emergence of accessible, high-capability mobile malware like ZeroDayRAT for the broader market. As mobile forensics tools become more adept at bypassing physical locks, the reliance on software-based encryption alone is no longer sufficient for high-risk individuals. True security now requires a combination of encrypted communications, hardware-level privacy controls, and constant vigilance against the evolving tactics of commercial spyware vendors.

This analysis is provided for educational and compliance purposes only; the use of surveillance tools is subject to strict international and local legal frameworks.

RedSec Technical Team

Cyber Intelligence & Hardware Engineering, RedSec LTD

RedSec LTD — reviewed for technical accuracy and lawful-use compliance.

Sources & References

Discuss Your Requirements

Speak with our intelligence team about hardware-modified spy phones and authorized surveillance capabilities.

Request a Consultation
Legal Notice

Authorized Use Only — Lawful Monitoring Required

SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.