New ZeroDayRAT Spyware Can Take Over iPhones and Androids
Published:
A newly identified mobile spyware toolkit called ZeroDayRAT is raising concerns among cybersecurity researchers. The software is reportedly being sold through online channels to cybercriminals and offers extensive control over both Android and iPhone devices.
Experts warn it can enable full remote access, exposing personal data, communications, and financial information.
The platform appears designed to be easy for criminals to use, even without advanced technical skills. Buyers reportedly receive a management dashboard that shows infected devices, activity timelines, and captured data in one place.
This makes it simpler to monitor victims, collect information, and potentially exploit compromised phones for financial or identity-related crimes.

Fig 1. The dashboard of ZeroDayRat showing two devices.
How the spyware spreads
Infection typically requires users to install a malicious file, often disguised as a legitimate app or shared through phishing messages. Text messages, emails, social media links, and unofficial app stores are common delivery methods.
Once installed, the spyware can quietly gather detailed information about the device. This may include phone model, operating system version, SIM details, recent messages, notifications, and account information linked to apps. Such data can help attackers profile victims, making further scams or account takeovers easier to carry out.

Fig 2. The surveillance options of ZeroDayRat including camera, screen and microphone monitoring
What attackers can do
Beyond passive data collection, the spyware reportedly enables real-time surveillance. Attackers may activate cameras or microphones, record screens, log keystrokes, and track GPS location history.
Combined together, these capabilities could allow criminals to monitor daily activities, capture passwords, and observe sensitive personal or professional communications.
Financial theft is a particularly serious risk. The malware may target banking apps, payment services, and cryptocurrency wallets by capturing login credentials, intercepting one-time security codes, or redirecting transactions.
Victims might only realize something is wrong after unauthorized payments, suspicious logins, or unusual financial activity appears.
Stopping distribution is challenging because each criminal can operate their own infrastructure rather than relying on a central server.
This decentralised approach makes law-enforcement takedowns more difficult and allows new operators to quickly replace those that are removed. Researchers believe the threat may persist for some time.

Fig 3. Tracking a phone’s location with ZeroDayRat.
How to stay safer
For everyday users, cautious behaviour remains one of the strongest protections. Installing apps only from official stores, avoiding unexpected links, and checking app permissions carefully can reduce risk.
Keeping phones updated and enabling built-in security features can also limit exposure to mobile spyware and similar threats.