A new generation of commercially marketed mobile surveillance platforms is reducing the technical barrier between sophisticated cyber-espionage capabilities and ordinary cybercrime. Explore what researchers have reported about ZeroDayRAT, how mobile spyware can compromise digital identity, communications and physical privacy, and how security teams can detect, investigate and contain advanced mobile threats.
Entity Definition
ZeroDayRAT is the name used for a commercially marketed mobile surveillance and remote-access platform documented by security researchers in 2026. Reported capabilities include device profiling, location monitoring, SMS and notification access, camera and microphone surveillance, screen monitoring, keylogging and financial targeting. Public evidence does not currently establish that the platform necessarily relies on a genuine zero-day or zero-click exploit.
ZeroDayRAT emerged publicly in security reporting in February 2026 as a commercially marketed mobile surveillance and remote-access (RAT) platform. Researchers described a centralized management interface through which an operator could issue instructions to an affected device and review collected information.
Because the platform is marketed commercially, different operators may control separate infrastructure. That distributed model complicates simple infrastructure-based attribution or takedown: blocking one operator's domains does not necessarily affect another's, and indicators observed in one incident may not generalise.
The name itself is a source of confusion. "ZeroDayRAT" is a product name, not a technical finding — and naming is not evidence.
Reported Capability Matrix
Each row separates what has been reported by researchers from what has only been advertised by sellers. Never treat an advertised capability as a confirmed one.
Reported ZeroDayRAT capabilities with security impact, evidence classification and defensive priority.
Despite the name, publicly available research has not established that ZeroDayRAT relies on an undisclosed zero-day vulnerability. Public reporting has discussed an "exploit" function visible in material associated with the platform, but independent researchers have not publicly confirmed a genuine ZeroDayRAT zero-day exploit chain.
A vulnerability unknown to or not yet patched by the responsible vendor when exploitation begins.
An attack requiring no deliberate interaction such as clicking a link or opening a malicious attachment.
Remote Access Trojan — malware designed to provide remote control or surveillance capabilities.
These terms describe different technical concepts and must not be treated as synonyms. A RAT is not automatically a zero-day. A zero-day is not automatically zero-click. A zero-click exploit is not automatically spyware. Spyware can be installed through social engineering without using any zero-day vulnerability.
Defensive Model
A conceptual lifecycle used to align defensive visibility and investigation questions to each stage. This lifecycle is educational and conceptual — it intentionally contains no infection procedures, payload generation steps, packaging methods or command-and-control deployment instructions.
Target selection and profiling from open or previously collected information.
A pretext persuades the target to install or approve something.
A mobile application or component is introduced onto the device.
Access is expanded through granted permissions or platform features.
Device, location, message, notification and input data are gathered.
An operator interface issues instructions and tunes collection.
Collected data is transferred to operator-controlled infrastructure.
Accounts, funds and privacy are affected downstream.
SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.