---
title: "What Is ZeroDayRAT? Evidence-classified overview (2026)"
description: "ZeroDayRAT is a commercially marketed mobile spyware and RAT platform first documented in 2026. This evidence-classified overview separates what public reporting establishes from what sellers claim."
evidence: "reported"
last_updated: "2026-08-31"
author: "Daniel Voss, Lead Threat Researcher"
canonical: "https://zerodayrat.shop/what-is-zerodayrat"
---

# What Is ZeroDayRAT?

**Evidence classification: Reported** — ZeroDayRAT is the name used for a commercially marketed mobile surveillance and remote-access (RAT) platform documented by security researchers in February 2026. Reported capabilities include device profiling, location monitoring, SMS and notification access, camera and microphone surveillance, screen monitoring, keylogging, and financial targeting. The platform is marketed commercially, meaning different operators may control separate infrastructure.

## Quick Answer

ZeroDayRAT is a commercially sold mobile spyware and remote-access trojan (RAT) platform that emerged in public security reporting in February 2026. It is marketed as a tool for device surveillance — location, messages, camera, microphone, screen, keystrokes — and is primarily associated with Android targeting. Despite the name, there is no public evidence that ZeroDayRAT uses a genuine zero-day exploit.

## Overview

ZeroDayRAT emerged publicly in security reporting in February 2026 as a commercially marketed mobile surveillance and remote-access platform. Researchers described a centralized management interface through which an operator could issue instructions to an affected device and review collected information.

Because the platform is marketed commercially, different operators may control separate infrastructure, complicating simple infrastructure-based attribution or takedown. This commercial model means the threat landscape is fragmented — each buyer runs their own servers, creating per-operator indicators rather than a single shared infrastructure.

## What Public Evidence Establishes

The following capabilities have been **reported** by credible security researchers:

- **Device profiling**: Collection of device identifiers, installed applications, and system information.
- **Location monitoring**: GPS-based location tracking and movement history.
- **SMS and notification access**: Interception of SMS messages and notification content.
- **Camera and microphone surveillance**: Remote activation of camera and microphone for audio/video capture.
- **Screen monitoring**: Real-time or periodic screen capture.
- **Keylogging**: Capture of keystrokes entered on the device.
- **Financial targeting**: OTP interception, credential overlay attacks, and clipboard manipulation targeting banking and cryptocurrency applications.

## What the Name Does Not Mean

The name "ZeroDayRAT" implies the use of a zero-day exploit. However:

- **No public demonstration** of a ZeroDayRAT zero-click infection chain exists.
- **No independently verified zero-day exploit** has been linked to ZeroDayRAT.
- The name is a **marketing label**, not a technical classification.

A zero-day exploit is a vulnerability that is exploited before the vendor has released a patch. Zero-click means the exploit requires no user interaction. Neither has been demonstrated for ZeroDayRAT in public reporting.

## Evidence Classification

| Level | Meaning |
|-------|---------|
| Observed | Directly observed in independent analysis or testing |
| Confirmed | Independently verified by multiple sources with technical evidence |
| Reported | Reported by credible security researchers but not fully independently verified |
| Advertised / Claimed | Claimed by the seller or operator; not independently verified |
| Unconfirmed | Cannot be confirmed or denied based on available public evidence |
| Analytical Assessment | Analytical conclusion based on reasoning from available evidence |

Most ZeroDayRAT capabilities are classified as **Reported** — they have been described by researchers but not independently demonstrated with published technical evidence.

## FAQ

### Does ZeroDayRAT need a zero-day to infect a phone?

No. The name implies a zero-day, but public reporting suggests ZeroDayRAT relies on social engineering, sideloaded apps, and permission abuse — not exploit chains. A zero-day is not required for most mobile spyware infections.

### How does ZeroDayRAT get on a phone?

Reported delivery methods include social engineering (phishing links, deceptive downloads), sideloaded APKs outside the Play Store, and permission abuse (accessibility services, notification access, overlay permissions). The user often installs the app themselves, tricked into granting permissions.

### Can I check if I'm infected?

Detection is difficult because spyware hides its icons and uses legitimate system permissions. Indicators include unusual battery drain, unexpected data usage, apps you don't recognize with accessibility permissions, and device behavior changes. See the [Detection Guide](/detection.md) for a multi-layer framework.

### Is the name "ZeroDayRAT" accurate?

No. The name is a marketing label, not a technical description. There is no public evidence that ZeroDayRAT uses a zero-day exploit or a zero-click infection chain.

## Sources

- [iVerify](https://iverify.com) — ZeroDayRAT mobile research reporting (February 2026)
- [SecurityWeek](https://securityweek.com) — coverage of advertised platform functionality
- [BleepingComputer](https://bleepingcomputer.com) — technical analysis reporting
- [ThaiCERT](https://thaicert.or.th) — advisory summarising reported functionality
- [Dark Reading](https://darkreading.com) — threat landscape analysis
