Back to Blog
Mobile Malware

ZeroDayRAT Uncovered: Cross-Platform Mobile Malware Targets iOS and Android

Cybersecurity researchers reveal ZeroDayRAT, a cross-platform mobile malware sold commercially to orchestrate real-time surveillance across Android and iOS.

ZeroDayRAT Uncovered: Cross-Platform Mobile Malware Targets iOS and Android

The Emergence of Cross-Platform Mobile Surveillance Platforms

Mobile security researchers have detailed a potent commercial surveillance threat dubbed ZeroDayRAT, an evasive strain of cellphone spyware engineered to operate concurrently across both major mobile operating systems. Disclosed by threat intelligence analysts, the campaign exemplifies the industrialization of off-the-shelf mobile exploitation. Unlike legacy tools restricted to single operating system kernels, ZeroDayRAT bridges the architectural divide by deploying distinct builders targeting Android builds from legacy iterations through current releases, as well as modern iOS environments.

Historically, enterprise security models treated Apple's walled garden as significantly more resilient against non-state-sponsored intrusion than Android’s modular ecosystem. However, commercial malware developers have pivoted. By selling turnkey binaries and centralized Command-and-Control architectures over encrypted messaging channels, criminal operators now access surveillance arsenals once reserved for advanced persistent threat (APT) groups. The proliferation of this tool underscores a severe reality for corporate executives and high-risk operatives: consumer hardware, regardless of vendor, is vulnerable to sophisticated mobile malware.

Delivery Vectors and Exploitation Architecture

ZeroDayRAT relies on dual-track delivery mechanisms engineered to bypass runtime sandboxing and native application vetting protocols. On Android systems, the malware proliferates through malicious application package (APK) files hosted across unofficial app stores, compromised open-source repositories, and social engineering channels. The implants leverage excessive permissions—predominantly targeting Accessibility Services and Device Administrator privileges—to intercept user interaction, harvest cryptographic keys, extract SMS verification codes, and capture keystrokes in real time.

On the iOS side, attackers systematically bypass App Store scrutiny by exploiting Apple Enterprise Developer Provisioning profiles. Intended originally for internal corporate mobile device management (MDM), these enterprise certificates allow operators to install cryptographically signed malicious packages directly onto targets without requiring App Store review. Furthermore, as regulatory shifts mandate sideloading support and alternate app ecosystems globally, threat actors gain expanded vectors to introduce repackaged, malicious software suites.

While state-sponsored actors frequently rely on complex zero-click exploit chains in messaging protocols, commercial syndicates maximize efficiency. By weaponizing social engineering with weaponized enterprise configuration payloads, attackers establish persistent footholds that resist standard user-initiated removals.

Command-and-Control Operations and Surveillance Capabilities

Once resident on the endpoint, ZeroDayRAT connects directly to operator-configured infrastructure via an interactive C2 dashboard. The platform provides threat actors with granular, real-time command execution, exfiltration, and exfiltration monitoring. Key forensic telemetry reveals the following live surveillance capabilities:

  • Real-Time Environment Surveillance: Remote background activation of peripheral hardware, enabling unauthorized room monitoring via internal microphones and video recording via device camera sensors.
  • Encrypted Data Infiltration: Harvesting of in-memory data, bypassing Link-Layer encryption and TLS controls by pulling message fragments before storage encryption takes place.
  • Geographical Tracking: Continuous high-precision GPS telemetry polling coupled with cell-tower triangulation data, exposing operational travel patterns.
  • Financial Asset Exfiltration: Specialized heuristic modules designed to parse optical galleries, scan documents for seed phrases, and intercept two-factor authentication tokens.

Because data exfiltration occurs directly at the operating system runtime layer, endpoint compromise renders secure transit protocols ineffective. When a device is compromised at the operating system or application runtime level, end-to-end encrypted communications can be scraped at the glass before mathematical ciphering occurs.

Technical Defenses: Countering Advanced Cellular Threats

Defending enterprise environments against modular mobile malware demands a paradigm shift away from traditional Mobile Threat Defense (MTD) software agents, which are inherently constrained by the very sandboxes they operate within. Security operations teams require active mobile forensics to audit system log artifacts, track anomalous background data transport, and inspect configuration profiles for malicious enterprise certificates.

Organizations handling sensitive operations increasingly deploy dedicated, tamper-resistant encrypted phones stripped of commercial tracking services, unneeded radio firmware, and standard consumer frameworks. At the highest operational tier, defeating persistent hardware-level compromises necessitates hardware-modified phones engineered with physical severance switches for baseband modems, cameras, and microphones. Physical isolation ensures that even if ZeroDayRAT executes within the operating system, it cannot conduct unauthorized audio, visual, or cellular interception.

Key Takeaway

The disclosure of ZeroDayRAT confirms that multi-platform commercial spyware has eliminated the operational security gap between Android and iOS. High-value individuals cannot rely solely on platform reputation; maintaining digital sovereignty now requires proactive zero-trust device architectures, hardened hardware, and rigorous profile management.

This technical analysis is published strictly for defensive forensic analysis, enterprise threat modeling, and lawful operational security compliance.

RedSec Technical Team

Cyber Intelligence & Hardware Engineering, RedSec LTD

RedSec LTD — reviewed for technical accuracy and lawful-use compliance.

Sources & References

Discuss Your Requirements

Speak with our intelligence team about hardware-modified spy phones and authorized surveillance capabilities.

Request a Consultation
Legal Notice

Authorized Use Only — Lawful Monitoring Required

SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.