A dark web listing claims to sell a zero-click mobile exploit chain under CVE-2026-32157 targeting RCS on Android and iOS. However, threat intelligence reveals this is a cryptocurrency scam exploiting a real Microsoft Remote Desktop vulnerability identifier to deceive buyers.

A Use-After-Free Remote Code Execution vulnerability in Microsoft Remote Desktop Client.
Crafted RCS/SMS/MMS Payload
Zero-Click Parser Exploit
Multi-Stage Memory-Resident Dropper
Surviving Reboots & Resets
Tor-Accessible Hidden Service (.onion)
If your team may be exposed to a similar threat, FemtoSec can help validate blast radius, prioritize remediation, and connect the issue to a practical security program.