Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft
ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft
Cybersecurity

ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft

•February 24, 2026
0
GBHackers On Security
GBHackers On Security•Feb 24, 2026

Companies Mentioned

Binance

Binance

PayPal

PayPal

PYPL

Why It Matters

The platform lowers the barrier for low‑skill criminals to conduct sophisticated espionage and monetary fraud on mobile devices, expanding the attack surface for enterprises and consumers alike.

Key Takeaways

  • •ZeroDayRAT offers unified surveillance and theft for Android/iOS.
  • •Service sold via Telegram, subscription starts at $250 daily.
  • •Smishing and fake app distribution are primary infection vectors.
  • •Clipboard injection hijacks crypto transfers; OTP interception bypasses 2FA.

Pulse Analysis

The emergence of mobile‑focused RATs as a Malware‑as‑a‑Service offering reflects a broader shift in cybercrime economics. By packaging advanced surveillance tools with financial‑theft modules, providers like ZeroDayRAT enable actors without deep technical expertise to rent turnkey capabilities. This commoditization accelerates the diffusion of sophisticated threats across the Android and iOS ecosystems, challenging traditional security models that have historically prioritized desktop environments. As mobile devices become primary gateways to personal finance and corporate data, the incentive for attackers to exploit them intensifies.

ZeroDayRAT’s technical arsenal combines classic espionage functions—live camera feeds, microphone activation, GPS tracking—with novel financial‑theft techniques such as clipboard injection and overlay attacks on popular payment apps. The integration of OTP interception further erodes two‑factor authentication, a cornerstone of modern security. While some promotional screenshots appear fabricated, the verified capabilities already enable credential harvesting, keylogging, and real‑time exfiltration of crypto wallet addresses, presenting a tangible risk to both individual users and organizations that permit BYOD policies.

Mitigating this evolving threat requires a layered approach. Enterprises should enforce strict mobile device management, restrict installation of unsigned applications, and deploy anti‑smishing awareness training. On the consumer side, users must verify app sources, scrutinize unexpected SMS links, and consider security solutions that monitor anomalous app behavior. As the MaaS market matures, regulators and security vendors are likely to introduce standards for mobile threat intelligence sharing, aiming to curtail the rapid adoption of services like ZeroDayRAT before they become entrenched in the cyber‑crime supply chain.

ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...