---
title: "ZeroDayRAT vs Pegasus: Key differences (2026)"
description: "ZeroDayRAT and Pegasus are both mobile spyware, but they occupy different tiers. This comparison covers capability, targeting, infrastructure, evidence, and cost — separating marketing from demonstrated capability."
evidence: "assessment"
last_updated: "2026-08-31"
author: "Daniel Voss, Lead Threat Researcher"
canonical: "https://zerodayrat.shop/zerodayrat-vs-pegasus"
---

# ZeroDayRAT vs Pegasus: Key Differences

**Evidence classification: Analytical Assessment** — This comparison is based on public reporting for both platforms. Pegasus has been extensively documented; ZeroDayRAT has not.

## Summary

ZeroDayRAT and Pegasus are both mobile spyware, but they occupy fundamentally different tiers of the threat landscape. Pegasus is a mercenary spyware platform developed by the NSO Group, extensively documented by researchers, and linked to targeted attacks against journalists, activists, and government officials. ZeroDayRAT is a commercially marketed RAT platform with reported Android-focused capabilities but far less independent verification.

| Dimension | ZeroDayRAT | Pegasus |
|-----------|-----------|---------|
| **Tier** | Commercial RAT | Mercenary spyware |
| **Evidence base** | Reported (Feb 2026) | Extensively documented |
| **Targeting** | Broad, commercial | Targeted, high-value |
| **iOS capability** | Advertised, unconfirmed | Demonstrated |
| **Zero-click** | No public evidence | Demonstrated (historical) |
| **Cost** | Low (commoditized) | Very high (government-grade) |
| **Infrastructure** | Per-operator (fragmented) | NSO-controlled |
| **Independent analysis** | Limited | Extensive (Citizen Lab, Amnesty) |

## Capability Comparison

### ZeroDayRAT (Reported)

- Device profiling, location, SMS, notifications
- Camera, microphone, screen monitoring
- Keylogging, clipboard manipulation
- OTP interception, credential overlay
- Primarily Android-focused
- iOS capability advertised but unconfirmed

### Pegasus (Documented)

- Full device access (root-level on compromised devices)
- Zero-click exploit chains (historical, now patched)
- Both Android and iOS targeting
- Self-destructing implants
- Encrypted C2 communication
- Extensively analyzed by Citizen Lab, Amnesty International, and Google Project Zero

## Targeting Model

**ZeroDayRAT** is sold commercially to multiple buyers. This means:
- Targeting is broad — any buyer can target anyone
- Each operator runs their own infrastructure
- Attribution is fragmented
- The threat is commoditized

**Pegasus** is sold to government clients only. This means:
- Targeting is selective — high-value individuals
- Infrastructure is controlled by NSO Group
- Attribution is more tractable
- The threat is exclusive

## Evidence Gap

The most important difference is **evidence**:

- **Pegasus** has been independently analyzed by Citizen Lab, Amnesty International (with the Pegasus Project), and Google Project Zero. Technical details, exploit chains, and IOCs are publicly documented.
- **ZeroDayRAT** has been reported by researchers in February 2026, but independent technical analysis is limited. Many capabilities are classified as "Advertised/Claimed" rather than "Confirmed."

## FAQ

### Is ZeroDayRAT as dangerous as Pegasus?

In terms of demonstrated capability, no. Pegasus has been shown to use zero-click exploit chains against fully patched devices. ZeroDayRAT relies on social engineering and permission abuse. However, for an individual target, both can result in full device compromise.

### Can ZeroDayRAT target iOS?

iOS capability is advertised but unconfirmed. Apple's sandboxing, code signing, and Lockdown Mode make iOS exploitation significantly harder. No public demonstration of ZeroDayRAT iOS compromise exists.

### Which is more common?

ZeroDayRAT, by virtue of its commercial model, is likely more widely deployed. Pegasus is restricted to government clients. But Pegasus targeting is more sophisticated and better resourced.

## Sources

- [iVerify](https://iverify.com) — ZeroDayRAT mobile research reporting
- [SecurityWeek](https://securityweek.com) — coverage of advertised platform functionality
- [BleepingComputer](https://bleepingcomputer.com) — technical analysis reporting
- [ThaiCERT](https://thaicert.or.th) — advisory summarising reported functionality
- [Dark Reading](https://darkreading.com) — threat landscape analysis
- [Citizen Lab](https://citizenlab.ca) — Pegasus research and documentation
- [Amnesty International](https://amnesty.org) — Pegasus Project investigation
