Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS
ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS
NEWS

ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS

A new mobile spyware platform called ZeroDayRAT supports Android 5-16 and iOS up to version 26, providing real-time camera streaming, keylogging, 2FA...

Dylan H.

News Desk

February 17, 2026
2 min read

Complete Mobile Compromise Toolkit

Security researchers have disclosed a new mobile spyware platform called ZeroDayRAT that provides nation-state-grade surveillance capabilities to a broader range of threat actors. The platform supports Android 5 through 16 and iOS up to version 26, making it one of the most comprehensive mobile compromise toolkits ever documented.


Capabilities

Surveillance Features

CapabilityDescription
Live CameraReal-time streaming from front and rear cameras
Screen RecordingContinuous screen capture with minimal battery impact
MicrophoneLive audio feed and ambient recording
GPS TrackingReal-time location tracking with geofencing
KeyloggingFull keystroke capture including passwords
SMS InterceptionRead all SMS including OTPs to defeat 2FA

Financial Targeting

  • Cryptocurrency wallets: MetaMask, Trust Wallet, Binance, Coinbase
  • Mobile payments: Apple Pay, Google Pay, PayPal
  • Banking apps: Session hijacking and credential theft

Distribution Method

ZeroDayRAT is distributed primarily via smishing (SMS phishing) campaigns. Victims receive messages impersonating:

  • Delivery notifications
  • Bank security alerts
  • Software update prompts
  • Government services

Why This Matters

Researchers describe ZeroDayRAT as "a complete mobile compromise toolkit comparable to kits previously requiring nation-state resources." The commoditization of such advanced spyware capabilities raises serious concerns about:

  • Targeted surveillance of journalists, activists, and dissidents
  • Financial theft via cryptocurrency and payment platform hijacking
  • Corporate espionage through real-time device monitoring
  • 2FA bypass rendering common security measures ineffective

Protective Measures

  1. Keep devices fully updated — apply all OS patches immediately
  2. Never click links in unexpected SMS messages
  3. Use hardware security keys instead of SMS-based 2FA
  4. Install apps only from official stores (App Store, Google Play)
  5. Enable lockdown mode on iOS for high-risk individuals
  6. Monitor for unusual battery drain or data usage spikes

The emergence of ZeroDayRAT underscores the growing accessibility of advanced surveillance tools and the critical need for mobile security awareness.

Related Reading

  • PromptSpy: First Android Malware to Weaponize Generative AI
  • Android March 2026 Security Update Patches 129
  • Apple Patches Actively Exploited iOS Zero-Day Used in
#Spyware#Mobile Security#iOS#Android#Surveillance#ZeroDayRAT#2FA Bypass

Related Articles

Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks

Apple warned iPhone users in 110 countries of mercenary spyware attacks. Enable Lockdown Mode and update iOS immediately if you receive an alert.

4 min read

Inside the Underground Business of BTMOB RAT

Flare researchers analyzed thousands of underground posts to reveal how the BTMOB Android RAT evolved from a single MaaS product into a fragmented ecosystem of resellers, source-code vendors, and independent fork operators.

6 min read

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Researchers at Hunt.io have traced the Flying Eagle Android remote access trojan framework to over 170 internet-exposed control panel servers, as its source code circulates freely through criminal Telegram channels.

5 min read
Back to all News