Your Phone Was Never Yours: How $2,000 Buys Total Access to Your Life

Somewhere right now, someone is watching a stranger’s phone screen in real time.

Not a government. Not the NSA. Not a shadowy intelligence agency with a classified budget and a three-letter name.

Just a person. With a Telegram account and two thousand dollars.

That’s the price of ZeroDayRAT—a commercial spyware platform that surfaced on February 2nd, 2026, and was immediately analyzed by mobile security researchers at iVerify. It’s being sold openly on Telegram, complete with dedicated sales channels, customer support, and regular updates. It works on Android 5 through 16 and iOS up to version 26, including the iPhone 17 Pro. The operator doesn’t need to write a single line of code.

For two thousand dollars, the buyer gets a control panel, a payload builder, and full remote access to someone’s phone.

Full access.

What “Full Access” Actually Means

We throw that phrase around loosely in security. So, let’s be specific about what this toolkit gives an operator once a device is compromised.

Live camera streaming—front and rear. Live microphone feed. Real-time screen recording. GPS tracking with full location history embedded in Google Maps. A keylogger that captures every keystroke, every gesture, every unlock pattern, timestamped down to the second. Full SMS access—which means intercepting every one-time password your bank, your email, and your MFA app sends you. The ability to send messages from your number. A notification log that captures everything from WhatsApp, Instagram, Telegram, YouTube, and more. A list of every account registered on your device—Google, Facebook, Amazon, PayPal, all of it. And a cryptocurrency module that scans for MetaMask, Trust Wallet, Binance, and Coinbase, records wallet IDs and balances, and swaps your copied wallet addresses with the attacker’s the moment you paste one.

Read that list again. That’s not surveillance. That’s ownership.

The attacker sees what you see. Hears what you hear. Knows where you are. Reads what you type. Intercepts your security codes before you do. And they can do all of it from a browser dashboard that looks like a CRM.

This Is Not a Nation-State Problem

A year ago, this kind of capability required a government contract or a mercenary spyware vendor like NSO Group. Tools like Pegasus made headlines precisely because they were rare, expensive, and deployed against journalists, dissidents, and heads of state. The conversation was always framed in geopolitics.

ZeroDayRAT changes the frame.

This isn’t Pegasus. It doesn’t use zero-click exploits. It doesn’t silently compromise your device through an iMessage you never opened. It requires the target to install a malicious app—typically delivered through a phishing text, a fake download link, or a trojanized app on a third-party store.

But that distinction doesn’t make it less dangerous. It makes it more dangerous—because the delivery method is the one that works on regular people every single day.

A text that says your package couldn’t be delivered. A link that says your bank needs to verify your identity. A message from a “friend” with an app recommendation. A fake update for something you already use. These aren’t exotic attacks. They’re the same lures that have worked since phishing was invented. The only difference is what’s on the other end now.

Before, clicking the wrong link might have gotten your credentials stolen or a piece of adware installed. Now, clicking the wrong link can hand someone your entire life in real time.

Who Actually Buys This

The security community calls ZeroDayRAT “textbook stalkerware,” and that label matters. Because the buyer profile for a $2,000 spyware kit isn’t a nation-state. It’s not even a sophisticated criminal organization.

It’s a jealous partner. A controlling ex. A private investigator cutting corners. A small-time scammer running romance fraud. A business competitor who wants to read your messages. An abusive parent tracking an adult child.

Daniel Kelley, a research fellow at iVerify, put it plainly: “The victim profile depends entirely on the buyer, but the price point and capability set suggest someone specific is always in mind.”

That’s the part that should sit with you. This isn’t spray-and-pray malware hoping to catch whoever it can. This is targeted surveillance, sold to people who already have a target picked out. The tool just gives them the access they were already looking for.

Why Your Defenses Won’t Catch It

ZeroDayRAT doesn’t trip the alarms most people rely on. It doesn’t behave like traditional malware because it isn’t traditional malware. Once installed, it operates through legitimate-looking system permissions—the same ones dozens of apps on your phone already use. Camera access. Microphone access. Notification access. SMS access. Location services.

Your phone doesn’t know the difference between a trusted app using those permissions and a malicious one abusing them. And neither does your antivirus, if you even have one on your phone. Most people don’t.

The operator’s infrastructure is self-hosted, which means there’s no central server for authorities to shut down. The toolkit is advertised in five languages—Portuguese, Russian, Chinese, Spanish, and English. The developers deliberately muddy attribution: they post in Chinese, use Russian domains, and target victims in India and the United States. None of it lines up, and researchers believe that’s intentional.

Even if law enforcement wanted to act, there’s no single door to kick in. The seller runs a storefront. The buyers run their own servers. The victims have no idea anything is wrong.

All Your Defenses Assume You’re Not Infected

We talk about phone security like it’s a solved problem. We tell people to use strong passwords. We tell them to enable two-factor authentication. We tell them to keep their software updated. And all of that is still good advice.

But ZeroDayRAT intercepts your one-time passwords before they reach you. It captures your keystrokes as you type your strong password. It reads your screen while you approve your MFA prompt. Every layer of security you’ve built assumes your device is clean. If it isn’t, none of it matters.

And the infection vector isn’t a sophisticated zero-day exploit. It’s a convincing text message. It’s the same attack that’s worked on human beings since the first phishing email was sent. We just keep underestimating it because it feels too simple to be the real threat.

What You Can Actually Do

The honest answer is that there’s no magic fix. But there are things that meaningfully reduce your exposure.

Never install apps from outside the official App Store or Google Play. Not from a link in a text. Not from a QR code. Not from a friend’s recommendation that takes you to a website instead of a store listing. If it doesn’t come from the store, it doesn’t go on your phone.

Treat any text message with a link the same way you’d treat an email from a stranger asking for your password. Because functionally, that’s exactly what it is now.

Review your app permissions regularly. If a flashlight app has access to your microphone, camera, and SMS, that’s not a flashlight app. If something you don’t recognize has accessibility permissions, remove it immediately.

If you’re a high-risk individual—a journalist, an activist, a domestic abuse survivor, anyone in a situation where someone might want to watch you—enable Lockdown Mode on iOS or Advanced Protection on Android. These features exist specifically for this threat. Use them.

And if you’re an organization with employees on BYOD devices accessing corporate email, VPN, and cloud apps from their personal phones: those phones are now part of your attack surface whether you like it or not. If a single employee’s device is compromised with something like ZeroDayRAT, the attacker has access to everything that phone touches. Treat mobile endpoints with the same urgency you treat your servers.

The Line That Was Crossed

ZeroDayRAT isn’t the first commercial spyware kit and it won’t be the last. What it represents is a line that’s been crossed and won’t be uncrossed.

Nation-state surveillance capabilities are now consumer products. The tools that used to require government budgets now require a Telegram account. The dashboard that used to sit inside an intelligence agency now runs in a browser tab. And the people being targeted are no longer political dissidents in authoritarian regimes. They’re your coworkers, your neighbors, your family members.

We’ve spent years telling people their phones are safe as long as they follow the rules. Update your software. Don’t click suspicious links. Use a strong password.

The rules haven’t changed. But the consequences of breaking them have.

Your phone is the most intimate device you own. It knows where you sleep, who you talk to, what you search for at 2 a.m., how much money you have, and what your face looks like from every angle. That’s not a phone. That’s a dossier. And right now, someone is selling the key to it on Telegram for less than a month’s rent.

Act like it.