Sale of ZeroDay C2 panel for iOS and Android with claimed zero-click full-chain exploitation
Dark Web2026-06-29, 12:53
For informational purposes only
Affected platforms: iOS 13–26.5+ on all chips, Android all versions
The seller positions the tool as a zero-click full-chain exploitation framework for iOS and Android, which supposedly allows infecting a device with a single link without any interaction from the victim.
According to the author's description, the exploitation chain starts with a browser RCE, then proceeds through an escape from the sandbox, obtains kernel read/write, and installs a persistent implant. The seller specifically emphasizes that the tool does not depend on a specific delivery channel: the link can be sent via SMS, email, QR code, WhatsApp, Telegram, or any other mechanism for sharing a URL.
The listings claim support for all iOS builds from iOS 13 to 26.5+ and all versions of Android. The seller also claims that the tool will adapt to all OS updates. The listings are accompanied by video demonstrations.
The claimed set of features is very extensive. The seller lists modules for extracting Keychain, SMS/MMS, WhatsApp ChatStorage.sqlite, Telegram Axolotl.sqlite, iMessage, Signal, contacts, file system, browser history, cookies, saved passwords, notes, calendar, Apple Health, Google Fit, Wi-Fi networks and passwords, SIM/IMSI/IMEI, call logs, Find My iPhone configuration, and a list of installed apps.
A separate section is dedicated to surveillance capabilities: real-time camera feed from the front and main camera, live microphone capture, GPS tracking, GPS timeline dump, screen recorder, clipboard logger, notification listener, and keylogger. According to the seller, the panel also supports remote terminal, multi-device management, real-time dashboard, geofencing, scheduled task automation, reboot-resistant persistence watchdog, C2 tunneling via HTTPS/DNS/ICMP/WebSocket, remote kill switch, and a trace-removal module.
In addition, some of the features are aimed at stealing cryptocurrency assets and banking data.
The description also includes offensive tooling for packaging and delivering payloads: custom exploit builder, payload generator for RCE/reverse shell/bind shell, phishing page customizer, exploit porter for SMS/email/QR/WhatsApp/Telegram, AES-256 and ChaCha20 payload encryption, and AV/AMSI/EDR obfuscation packer.
Products