# ZeroDayRAT Intelligence Center > Independent threat intelligence and defensive analysis of the ZeroDayRAT commercial mobile spyware platform. Evidence-classified reporting for security teams, CISOs, and defenders. We do not publish exploit code or deployment instructions. Evidence classification system: Observed | Confirmed | Reported | Advertised/Claimed | Unconfirmed | Analytical Assessment ## Markdown Resources (for answer engines) - [What Is ZeroDayRAT?](/what-is-zerodayrat.md): Evidence-classified overview of the ZeroDayRAT mobile spyware platform — definition, reported capabilities, and what public evidence actually establishes - [Technical Analysis](/technical-analysis.md): Architecture, collection layers, and defensive telemetry mapping — how endpoint compromise defeats encryption - [Detection Guide](/detection.md): Multi-layer detection indicators (device, behavioral, identity, network) and triage framework - [Incident Response](/incident-response.md): Mobile spyware IR playbook — isolate, preserve, investigate, remediate, credential reset - [ZeroDayRAT vs Pegasus](/zerodayrat-vs-pegasus.md): Comparison with mercenary spyware — capability, targeting, infrastructure, and evidence differences - [ZeroDayRAT vs Stalkerware](/zerodayrat-vs-stalkerware.md): Banking trojan and spyware taxonomy — where ZeroDayRAT sits between commercial stalkerware and mercenary spyware - [Zero-Day vs Zero-Click vs RAT](/zero-day-vs-zero-click-vs-rat.md): Terminology reference — why ZeroDayRAT's name is not evidence of a zero-day - [Android Security](/android.md): Android attack surface and defender controls — sideloading, accessibility, permissions, MDM, MTD - [iOS Security](/ios.md): iOS threat assessment — sandbox, entitlements, Lockdown Mode, and why iOS claims need stricter evidence ## Author Daniel Voss, Lead Threat Researcher, ZeroDayRAT Intelligence Center ## Editorial Standards - Evidence-based: every claim is classified by confidence level (Observed, Confirmed, Reported, Advertised/Claimed, Unconfirmed, Analytical Assessment) - No exploit code, payloads, or deployment instructions published - Independent: not affiliated with any spyware vendor, security vendor, or government agency - Corrections are transparent and tracked at /corrections - Sources are cited with outbound links to primary research ## Primary Sources - iVerify (iverify.com) — ZeroDayRAT mobile research reporting, February 2026 - SecurityWeek (securityweek.com) — coverage of advertised platform functionality - BleepingComputer (bleepingcomputer.com) — technical analysis reporting - ThaiCERT (thaicert.or.th) — advisory summarising reported functionality - Dark Reading (darkreading.com) — threat landscape analysis