< Back to all clusters
[TECHNOLOGY] · China · 13 sources

started · updated

RatHat Android malware uses generative AI to steal credentials

Security researchers at Zimperium’s zLabs have identified a sophisticated new Android Trojan named RatHat. The malware distinguishes itself by integrating a generative AI assistant to automate device navigation and control. By accessing the device’s accessibility tree, the AI can interpret screen content in real time and execute commands such as scrolling or tapping, allowing the malware to bypass traditional rule-based security tools.

RatHat employs a multi-stage infection process, often initiated through smishing (SMS phishing) or malicious advertisements that trick users into sideloading malicious APK files. Once installed, the malware pressures users to enable Android’s Accessibility Services. It then exploits the Android Debug Bridge (ADB) by enabling Wireless Debugging and autonomously pairing with the device. This allows the Trojan to escape the standard app sandbox and deploy native binaries with elevated shell-level privileges.

A critical feature of RatHat is its ability to maintain persistence. It can install components that operate independently of the original application, meaning the malware may remain on a device even after the malicious app is uninstalled. It is also capable of detecting and blocking uninstallation attempts by displaying fake error messages. The malware specifically targets financial data, capable of intercepting two-factor authentication (2FA) codes, stealing banking credentials, and capturing screen content to facilitate unauthorized transactions.

Entities

Android · Elastic Security Labs · Google Chrome · Microsoft Edge · RatHat · Zimperium · zLabs