News Room
16
Share
ZeroDayRAT Expansion: Commercial Spyware Targets iOS 26 and Android 16 in New August Campaign
criticalOffensive Tools

ZeroDayRAT Expansion: Commercial Spyware Targets iOS 26 and Android 16 in New August Campaign

Encrygma analysts have identified a surge in ZeroDayRAT activity, a commercial spyware platform sold on Telegram that facilitates real-time surveillance and financial theft on the latest mobile OS versions.

03 August 2026Last updated 20 August 20264 min readiVerify
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
Source:
iVerify
Read Time:
4 min

Executive Summary

As of August 3, 2026, Encrygma intelligence has observed a sharp increase in the distribution of ZeroDayRAT, a sophisticated mobile surveillance tool. Initially disclosed earlier this year, the platform has evolved into a full-service 'spyware-as-a-service' model, targeting the latest iterations of mobile operating systems, including iOS 26 and Android 16. Recent activity suggests that the developers have integrated new exploits likely acquired from high-tier exploit brokers, expanding their reach to include financial theft alongside traditional espionage.

Threat Analysis

The landscape of mercenary spyware is shifting from exclusive, nation-state-only tools to commercially available platforms. ZeroDayRAT represents this democratization of high-end surveillance. According to reports from iVerify, these tools are now 'open for business,' providing cybercriminals with capabilities previously reserved for intelligence agencies. The threat is no longer limited to political dissidents or journalists; it now encompasses corporate executives and high-net-worth individuals who are targeted for both data and direct financial assets.

Technical Details

ZeroDayRAT utilizes a combination of 0-click and 1-click delivery mechanisms. On iOS 26, it has been observed leveraging vulnerabilities in the media processing framework to achieve remote code execution (RCE) without user interaction. On Android 16, the spyware exploits flaws in the hardware abstraction layer to bypass modern sandboxing. Once installed, the RAT provides a comprehensive command-and-control (C2) interface via Telegram, allowing operators to stream live audio, capture camera feeds, and exfiltrate encrypted messages from apps like WhatsApp and Signal. Technical analysis by The Hacker News confirms its ability to facilitate direct financial theft by intercepting one-time passwords (OTPs) and manipulating banking applications.

Attribution Assessment

While the primary developers of ZeroDayRAT operate through pseudonymous Telegram channels, their infrastructure shows overlaps with known exploit broker networks. The U.S. Treasury's recent sanctions against Matrix LLC (Operation Zero) highlight the ecosystem where these tools are born. It is assessed with high confidence that ZeroDayRAT developers are customers of such brokers, purchasing stolen or researched zero-day exploits to maintain their platform's efficacy against patched systems.

Implications

The availability of ZeroDayRAT signals a critical failure in the current mobile security paradigm. As noted by Guard Pear Software, the evolution of these tools outpaces the defensive updates from Apple and Google. For enterprises, this means that standard Mobile Device Management (MDM) solutions are no longer sufficient, as these spyware variants are designed to remain invisible to traditional management profiles and can persist through standard reboots.

Recommendations

Encrygma recommends the following immediate actions: 1. Enforce immediate updates to the latest security patches for iOS 26 and Android 16. 2. Implement 'Lockdown Mode' for high-risk personnel to reduce the attack surface. 3. Deploy advanced mobile threat defense (MTD) solutions that monitor for anomalous kernel-level activity. 4. Conduct regular audits of device logs for known C2 indicators associated with ZeroDayRAT and similar commercial surveillanceware.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo