ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft
## Cybersecurity: ZeroDayRAT Malware Update
Cybersecurity: ZeroDayRAT Malware Update
ZeroDayRAT targets Android and iOS devices, integrating real-time surveillance and financial theft capabilities within a single browser panel.
The Malware-as-a-Service (MaaS) platform is advancing by combining mobile surveillance and financial crime capabilities. ZeroDayRAT, promoted on February 2, 2026, offers dual functions: real-time spying and financial theft via a user-friendly browser dashboard.
After acquiring access through Telegram, attackers deploy an infected APK for Android or a malicious payload for iOS. Once installed, the malware enables full control over the victim's device, including live feeds, communications, and banking activities.
ZeroDayRAT compromises the user's digital behavior, physical surroundings, and financial data. Cyberthint researchers have uncovered this mobile spyware service, which allows non-technical actors to perform sophisticated spying and theft operations on both Android and iOS devices.
Infection Vectors and Control Panel Access
The RAT primarily spreads through smishing campaigns—fraudulent SMS messages mimicking legitimate service providers or app updates. Attackers also distribute fake versions of popular apps via WhatsApp, Telegram, and unauthorized app stores.
Once a device is compromised, attackers access a web control panel compatible with the latest OS versions (Android 16 and iOS 26.2). This interface provides a digital profile of the victim, showing the device model, carrier, most-used apps, and recent SMS interactions.
ZeroDayRAT targets Android and iOS devices, integrating real-time surveillance and financial theft capabilities within a single browser panel.
ZeroDayRAT transforms a compromised phone into a live surveillance tool, tracking GPS coordinates, monitoring location history, and remotely activating the camera and microphone. It also supports ambient listening and screen recording.
Its integrated keylogger captures every keystroke and biometric input with millisecond precision. Clipboard data and app transition logs are exfiltrated to the command panel for comprehensive behavioral analysis.
The RAT’s financial theft modules facilitate direct revenue generation. Using clipboard injection, it hijacks cryptocurrency transfers by replacing copied wallet addresses with the attacker’s own. Overlay attacks impersonate login screens for various payment and banking apps to harvest credentials.
ZeroDayRAT is offered under a tiered subscription model: $250 daily, $1000 weekly, or $3500 monthly. Threat researchers verified through Telegram interactions that the seller uses XSS Forum's Escrow service, indicating a level of legitimacy uncommon among scam vendors.
Integrated OTP interception captures two-factor authentication codes from SMS to bypass security measures in real-time.
Technical Observations and Credibility
While ZeroDayRAT poses a substantial risk, analysts noted some anomalies. A screenshot of its cryptocurrency theft module showed a questionable browser tab label, suggesting potential exaggeration of its capabilities.
ZeroDayRAT exemplifies the evolving threat landscape, allowing cybercriminals to conduct state-grade espionage through rental kits. It joins other mobile malware families like Anatsa and NFCShare, exploiting digital habits for data and financial infiltration.
As mobile RATs evolve, vigilance against smishing schemes and unknown app installations remains crucial, emphasizing that significant threats often stem from minor actions.
Based on reporting by GBHackers.
