TL;DR: Security researchers at iVerify have exposed ZeroDayRAT, a commercial spyware platform selling on Telegram for $2,000. Buyers get a turnkey surveillance kit: live camera and microphone feeds, real-time GPS tracking, keylogging, SMS interception (including two-factor codes), and modules to drain bank accounts and crypto wallets. It targets both Android (versions 5-16) and iOS (up to version 26). Infection starts with a phishing text or fake app. This isn't nation-state malware anymore. It's consumer-grade surveillance for anyone with two grand and bad intentions.
NSO Pegasus for the Rest of Us
ZeroDayRAT showed up on Telegram in early February 2026, advertised in five languages: English, Spanish, Portuguese, Russian, and Chinese [1]. For $2,000, buyers get access to a web-based control panel that turns any phone into a surveillance device.
The developer runs dedicated Telegram channels for sales, customer support, and regular updates. It's a full commercial operation, helpdesk and all [2].
Once installed on a target's phone, ZeroDayRAT gives operators:
- Live camera streaming: Front and back cameras, in real time
- Microphone access: Listen to conversations as they happen
- Screen recording: Watch exactly what the victim sees
- GPS tracking: Real-time location plotted on Google Maps, plus full location history
- Keylogging: Every keystroke, timestamped
- SMS interception: Including one-time passwords sent for two-factor authentication
- Account enumeration: Lists every logged-in account: Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, banking apps, payment services
But it doesn't stop at surveillance. ZeroDayRAT also steals money.
It's Also a Bank Robber
The spyware includes dedicated modules for financial theft [3]:
- Crypto wallet stealer: Scans for MetaMask, Trust Wallet, Binance, and Coinbase. Logs wallet IDs and balances. Uses clipboard hijacking to swap wallet addresses when victims try to send crypto.
- Bank account access: Targets Apple Pay, Google Pay, PayPal, and PhonePe (India's major UPI payment app)
- Overlay attacks: Places fake login screens over legitimate banking apps to harvest credentials
The SMS interception is key here. Even if you have two-factor authentication enabled, ZeroDayRAT can read the codes before you do. Your bank sends a verification code, the attacker sees it instantly, and they're into your account.
How It Gets on Your Phone
ZeroDayRAT doesn't exploit some exotic zero-day vulnerability. It uses the oldest trick in the book: tricking you into installing it [4].
The infection vectors reported so far:
- Smishing: Phishing texts that link to fake apps ("Your package is delayed, click here to track")
- Phishing emails: Links to malicious APK files for Android or sideloaded iOS apps
- Fake app stores: Clone marketplaces hosting trojanized versions of popular apps
- Malicious links on messaging platforms: WhatsApp, Telegram, Signal, anywhere a link can be clicked
Once the victim installs what looks like a normal app, ZeroDayRAT burrows into the system. On Android, it requests accessibility permissions (standard for stalkerware). On iOS, it's less clear how deep the compromise goes, but the developers claim support through iOS 26.
Who's Buying This?
The $2,000 price point tells you everything. It's too expensive for random trolls but accessible to:
- Abusive partners and stalkers: The primary market for commercial spyware. They want to monitor texts, calls, and location without the victim knowing.
- Private investigators: Operating in legal gray zones (or outright illegally)
- Corporate espionage: Targeting executives and employees with access to valuable data
- Small-time criminals: The crypto and banking theft modules make this a potential moneymaker
This is the democratization of NSO Group's business model. Pegasus costs millions and targets journalists and dissidents. ZeroDayRAT costs $2,000 and targets whoever the buyer wants to surveil.
How to Protect Yourself
Don't Click Links in Texts From Unknown Numbers
This is how most infections start. Package tracking, bank alerts, security warnings: if you didn't initiate the interaction, don't click the link. Go directly to the company's website or app.
Only Install Apps From Official Stores
Stick to Google Play and the Apple App Store. Even then, check reviews and developer info. On Android, make sure "Install unknown apps" is disabled for all apps in Settings > Security.
Review App Permissions
On Android: Settings > Apps > [App Name] > Permissions. Any app asking for camera, microphone, accessibility, and location all at once is suspicious. Legitimate apps rarely need everything.
Use Hardware Security Keys for 2FA
SMS-based two-factor authentication is vulnerable to interception. Switch to hardware security keys (YubiKey, Google Titan) or authenticator apps. Even if spyware intercepts your SMS, it can't touch a physical key.
Check for Stalkerware
Android: Look for apps with generic names ("System Service," "Phone Manager") that have excessive permissions. Check Settings > Security > Device Admin Apps for unknown entries.
iPhone: Review Settings > General > VPN & Device Management for unfamiliar profiles. Check Settings > [Your Name] > Devices for unknown devices signed into your Apple ID.
Use Mobile Security Software
iVerify (the researchers who discovered ZeroDayRAT) offers mobile threat detection for iOS and Android. Lookout and Malwarebytes also detect known stalkerware signatures.
The Spyware Industry's New Normal
ZeroDayRAT represents where commercial surveillance is heading. Not state-sponsored hacking tools reserved for intelligence agencies, but off-the-shelf kits anyone can buy and deploy.
The stalkerware industry has been breached 27 times since 2017, exposing millions of victims and customers. Yet the market keeps growing because demand keeps growing. Jealous partners, controlling parents, abusive spouses: they're willing to pay for this capability.
At $2,000, ZeroDayRAT isn't even the most expensive option. NSO Group's Pegasus reportedly costs millions. Circles and Candiru charge six figures. The price keeps dropping as the tools get more commoditized.
Your phone contains everything: your location, your conversations, your finances, your photos, your entire digital life. For a couple thousand dollars, someone can see all of it. The only defense is awareness, and not clicking that suspicious link.
References
- The Hacker News - New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft (February 2026)
- iVerify - Breaking Down ZeroDayRAT: New Spyware Targeting Android and iOS (February 2026)
- Security Affairs - ZeroDayRAT spyware grants attackers total access to mobile devices (February 2026)
- Tom's Guide - New ZeroDayRat spyware gives hackers total control over your iPhone or Android via text (February 2026)