Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft

0
Medium
Vulnerabilityandroidiosmobile
Published: Mon Feb 16 2026 (02/16/2026, 10:24:00 UTC)
Source: The Hacker News

Description

Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that's being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. "The developer runs dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a fully operational spyware

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 02/16/2026, 13:38:11 UTC

Technical Analysis

ZeroDayRAT is a sophisticated mobile spyware platform recently uncovered by cybersecurity researchers. It targets both Android and iOS operating systems, enabling attackers to conduct real-time surveillance and exfiltrate sensitive data from compromised devices. The spyware is distributed via Telegram channels operated by the developer, which provide sales, customer support, and regular updates, effectively commercializing the spyware as a service. This approach lowers the barrier to entry for threat actors, allowing even less technically skilled attackers to deploy advanced mobile surveillance tools. Although specific affected versions of mobile OS or apps are not detailed, the spyware’s capability to operate on both major mobile platforms indicates exploitation of either zero-day vulnerabilities or social engineering techniques to gain installation and persistence. The absence of known exploits in the wild suggests the spyware is either newly released or still in limited use, but its availability on Telegram signals a potential for rapid proliferation. The spyware’s functionalities likely include access to device sensors, messages, call logs, location data, and possibly microphone and camera control, enabling comprehensive monitoring. The medium severity rating reflects the spyware’s invasive capabilities balanced against the current lack of widespread exploitation evidence. The technical details emphasize the importance of monitoring Telegram and similar platforms for emerging threats and the need for mobile threat detection solutions capable of identifying such spyware.

Potential Impact

For European organizations, ZeroDayRAT poses a significant risk to confidentiality and privacy, particularly for sectors handling sensitive or classified information such as government, finance, healthcare, and critical infrastructure. The spyware’s ability to conduct real-time surveillance and data theft can lead to intellectual property loss, espionage, and reputational damage. The impact extends beyond individual users to organizational networks if infected devices are used to access corporate resources. Given the widespread use of Android and iOS devices across Europe, the potential attack surface is large. The spyware could facilitate targeted attacks against high-value individuals or groups, undermining trust in mobile communications and potentially disrupting operations. The lack of known exploits in the wild currently limits immediate impact, but the commercial availability and active promotion suggest a high likelihood of future exploitation. European organizations may face challenges in detection due to the spyware’s stealth capabilities and the difficulty of applying patches or updates to mobile OS components exploited by zero-day vulnerabilities. The threat also raises privacy concerns under GDPR regulations, with potential legal and compliance ramifications if personal data is compromised.

Mitigation Recommendations

European organizations should implement a multi-layered mobile security strategy beyond standard advice. This includes deploying advanced mobile threat defense (MTD) solutions capable of detecting spyware behaviors such as unusual sensor access, unauthorized background activity, or anomalous network communications. Enforce strict mobile device management (MDM) policies to restrict installation of apps from unofficial sources and control app permissions rigorously. Regularly educate employees about the risks of installing apps from untrusted sources, especially messaging platforms like Telegram where such spyware is marketed. Monitor threat intelligence feeds and Telegram channels for emerging spyware variants and indicators of compromise. Implement network-level controls to detect and block suspicious outbound connections from mobile devices. Encourage timely OS and app updates, even though zero-day exploits may not yet have patches, to reduce the attack surface. For high-risk users, consider using hardened or managed devices with restricted capabilities. Finally, establish incident response plans specific to mobile spyware infections to enable rapid containment and remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://thehackernews.com/2026/02/new-zerodayrat-mobile-spyware-enables.html","fetched":true,"fetchedAt":"2026-02-16T13:37:38.224Z","wordCount":2172}

Threat ID: 69931da4d1735ca731873d16

Added to database: 2/16/2026, 1:37:40 PM

Last enriched: 2/16/2026, 1:38:11 PM

Last updated: 4/2/2026, 11:48:34 PM

Views: 188

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses