
ZeroDayRAT Expansion: Commercial Spyware Targets iOS 26 and Android 16 in New August Campaign
Encrygma analysts have identified a surge in ZeroDayRAT activity, a commercial spyware platform sold on Telegram that facilitates real-time surveillance and financial theft on the latest mobile OS versions.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- iVerify
- Read Time:
- 4 min
Executive Summary
As of August 3, 2026, Encrygma intelligence has observed a sharp increase in the distribution of ZeroDayRAT, a sophisticated mobile surveillance tool. Initially disclosed earlier this year, the platform has evolved into a full-service 'spyware-as-a-service' model, targeting the latest iterations of mobile operating systems, including iOS 26 and Android 16. Recent activity suggests that the developers have integrated new exploits likely acquired from high-tier exploit brokers, expanding their reach to include financial theft alongside traditional espionage.
Threat Analysis
The landscape of mercenary spyware is shifting from exclusive, nation-state-only tools to commercially available platforms. ZeroDayRAT represents this democratization of high-end surveillance. According to reports from iVerify, these tools are now 'open for business,' providing cybercriminals with capabilities previously reserved for intelligence agencies. The threat is no longer limited to political dissidents or journalists; it now encompasses corporate executives and high-net-worth individuals who are targeted for both data and direct financial assets.
Technical Details
ZeroDayRAT utilizes a combination of 0-click and 1-click delivery mechanisms. On iOS 26, it has been observed leveraging vulnerabilities in the media processing framework to achieve remote code execution (RCE) without user interaction. On Android 16, the spyware exploits flaws in the hardware abstraction layer to bypass modern sandboxing. Once installed, the RAT provides a comprehensive command-and-control (C2) interface via Telegram, allowing operators to stream live audio, capture camera feeds, and exfiltrate encrypted messages from apps like WhatsApp and Signal. Technical analysis by The Hacker News confirms its ability to facilitate direct financial theft by intercepting one-time passwords (OTPs) and manipulating banking applications.
Attribution Assessment
While the primary developers of ZeroDayRAT operate through pseudonymous Telegram channels, their infrastructure shows overlaps with known exploit broker networks. The U.S. Treasury's recent sanctions against Matrix LLC (Operation Zero) highlight the ecosystem where these tools are born. It is assessed with high confidence that ZeroDayRAT developers are customers of such brokers, purchasing stolen or researched zero-day exploits to maintain their platform's efficacy against patched systems.
Implications
The availability of ZeroDayRAT signals a critical failure in the current mobile security paradigm. As noted by Guard Pear Software, the evolution of these tools outpaces the defensive updates from Apple and Google. For enterprises, this means that standard Mobile Device Management (MDM) solutions are no longer sufficient, as these spyware variants are designed to remain invisible to traditional management profiles and can persist through standard reboots.
Recommendations
Encrygma recommends the following immediate actions: 1. Enforce immediate updates to the latest security patches for iOS 26 and Android 16. 2. Implement 'Lockdown Mode' for high-risk personnel to reduce the attack surface. 3. Deploy advanced mobile threat defense (MTD) solutions that monitor for anomalous kernel-level activity. 4. Conduct regular audits of device logs for known C2 indicators associated with ZeroDayRAT and similar commercial surveillanceware.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
