started · updated
RatHat malware uses generative AI to target Android devices
Security researchers at Zimperium have identified a sophisticated new Android malware named RatHat, which is reportedly linked to threat actors in China. The malware distinguishes itself by integrating generative artificial intelligence to automate its operations, allowing it to interpret screen content and make autonomous decisions on where to tap, scroll, or click.
RatHat typically infects devices through social engineering, such as phishing SMS messages, malicious advertisements, or fraudulent websites mimicking the Google Play Store. Once installed, the malware requests Android Accessibility Service permissions. With this access, it can activate Developer Options and Wireless Debugging to gain shell-level control via the Android Debug Bridge (ADB).
The malware is capable of significant data theft, including intercepting SMS messages, one-time passwords (OTP), and two-factor authentication (2FA) codes. It can also record screen touches to reconstruct PINs and unlock patterns, and deploy fake login overlays to steal banking and cryptocurrency credentials. Its ability to adapt to different user interfaces makes it more difficult for traditional security software to detect compared to scripted malware.
Entities
Android · China · Google · Google Play Store · Malwarebytes · RatHat · Zimperium
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] The malware can record screen touches to reconstruct PINs and unlock patterns. ipaddisti.it · me.mashable.com · sea.mashable.com · mashable.com
- [● 8 SOURCES] The malware can activate Wireless Debugging to gain shell-level access via ADB. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 5 SOURCES] RatHat is linked to threat actors based in China. arenait.ro · me.mashable.com · sea.mashable.com · time.news · mashable.com
- [● 9 SOURCES] The malware uses generative AI to interpret screen content and make autonomous navigation decisions. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · que.com · +4 more
- [● 8 SOURCES] RatHat exploits Android Accessibility Services to gain control. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 9 SOURCES] RatHat is a new Android malware strain discovered by Zimperium researchers. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · que.com · +4 more
- [● 8 SOURCES] RatHat can intercept SMS, OTP codes, and two-factor authentication (2FA) data. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 7 SOURCES] The malware spreads via phishing SMS, malicious ads, and fake Google Play Store pages. gateeg.com · arenait.ro · ipaddisti.it · me.mashable.com · sea.mashable.com · +2 more