Independent Threat Intelligence · Mobile Spyware Research

ZeroDayRAT: Inside the New Generation of Mobile Spyware

A new generation of commercially marketed mobile surveillance platforms is reducing the technical barrier between sophisticated cyber-espionage capabilities and ordinary cybercrime. Explore what researchers have reported about ZeroDayRAT, how mobile spyware can compromise digital identity, communications and physical privacy, and how security teams can detect, investigate and contain advanced mobile threats.

Entity Definition

What Is ZeroDayRAT?

ZeroDayRAT is the name used for a commercially marketed mobile surveillance and remote-access platform documented by security researchers in 2026. Reported capabilities include device profiling, location monitoring, SMS and notification access, camera and microphone surveillance, screen monitoring, keylogging and financial targeting. Public evidence does not currently establish that the platform necessarily relies on a genuine zero-day or zero-click exploit.

ZeroDayRAT emerged publicly in security reporting in February 2026 as a commercially marketed mobile surveillance and remote-access (RAT) platform. Researchers described a centralized management interface through which an operator could issue instructions to an affected device and review collected information.

Because the platform is marketed commercially, different operators may control separate infrastructure. That distributed model complicates simple infrastructure-based attribution or takedown: blocking one operator's domains does not necessarily affect another's, and indicators observed in one incident may not generalise.

The name itself is a source of confusion. "ZeroDayRAT" is a product name, not a technical finding — and naming is not evidence.

Reported Capability Matrix

What Can ZeroDayRAT Reportedly Access?

Each row separates what has been reported by researchers from what has only been advertised by sellers. Never treat an advertised capability as a confirmed one.

Capability
Security Impact
Evidence
Priority
Device profiling / fingerprinting
Handset model, OS build, battery and locale data let an operator tailor follow-on activity and recognise the same device over time.
Reported
Medium
SIM and carrier information
Carrier, SIM identifiers and country data support geographic profiling and SMS-dependent attack planning.
Reported
Medium
Application intelligence
Installed-app lists and usage visibility reveal which banking, messaging, authenticator and corporate apps exist on the device.
Reported
High
Location tracking
Real-time position data creates physical-safety and travel-pattern exposure.
Reported
High
Location history
Historic movement builds a pattern-of-life profile far more sensitive than any single position.
Reported
High
SMS collection
SMS access exposes conversations and, critically, SMS-delivered one-time codes.
Reported
Critical
Notification visibility
Notification access can surface message previews, codes and alerts from otherwise protected apps.
Reported
Critical
Account identification
Enumerating device accounts maps the user's identity surface — mail, cloud and social identities.
Reported
High
Camera surveillance
Camera access converts a phone into an environmental sensor in homes, offices and meetings.
Advertised / Claimed
Critical
Microphone surveillance
Audio capture exposes conversations that never touch a network service.
Advertised / Claimed
Critical
Screen capture / monitoring
Screen visibility exposes anything the user sees, including decrypted messages.
Reported
Critical
Input monitoring / keylogging
Input capture can expose typed passwords, PINs, seed phrases and message drafts.
Reported
Critical
OTP exposure
Access to SMS and notifications can expose one-time codes and weaken step-up authentication.
Reported
Critical
Banking credential targeting
Credential targeting against banking and payment apps creates direct financial loss risk.
Advertised / Claimed
Critical
Cryptocurrency targeting
Wallet targeting and clipboard interference can redirect funds or expose recovery material.
Advertised / Claimed
Critical
Clipboard manipulation
Reading or replacing clipboard content can silently substitute payment addresses.
Reported
High
Remote administration
A management interface lets an operator issue commands and adjust collection over time.
Reported
Critical

Reported ZeroDayRAT capabilities with security impact, evidence classification and defensive priority.

Terminology Correction

ZeroDayRAT ≠ Confirmed Zero-Day

Despite the name, publicly available research has not established that ZeroDayRAT relies on an undisclosed zero-day vulnerability. Public reporting has discussed an "exploit" function visible in material associated with the platform, but independent researchers have not publicly confirmed a genuine ZeroDayRAT zero-day exploit chain.

Zero-Day

A vulnerability unknown to or not yet patched by the responsible vendor when exploitation begins.

Zero-Click

An attack requiring no deliberate interaction such as clicking a link or opening a malicious attachment.

RAT

Remote Access Trojan — malware designed to provide remote control or surveillance capabilities.

These terms describe different technical concepts and must not be treated as synonyms. A RAT is not automatically a zero-day. A zero-day is not automatically zero-click. A zero-click exploit is not automatically spyware. Spyware can be installed through social engineering without using any zero-day vulnerability.

Defensive Model

Understanding the Mobile Spyware Attack Chain

A conceptual lifecycle used to align defensive visibility and investigation questions to each stage. This lifecycle is educational and conceptual — it intentionally contains no infection procedures, payload generation steps, packaging methods or command-and-control deployment instructions.

STAGE 01

Reconnaissance

Target selection and profiling from open or previously collected information.

STAGE 02

Social Engineering / Delivery

A pretext persuades the target to install or approve something.

STAGE 03

Malicious Mobile Component

A mobile application or component is introduced onto the device.

STAGE 04

Permission or Execution Stage

Access is expanded through granted permissions or platform features.

STAGE 05

Collection

Device, location, message, notification and input data are gathered.

STAGE 06

Remote Control

An operator interface issues instructions and tunes collection.

STAGE 07

Exfiltration

Collected data is transferred to operator-controlled infrastructure.

STAGE 08

Identity / Financial / Surveillance Impact

Accounts, funds and privacy are affected downstream.

Legal Notice

Authorized Use Only — Lawful Monitoring Required

SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.