< Back to all clusters
[TECHNOLOGY] · China · 11 sources

started · updated

RatHat malware uses generative AI to target Android devices

Security researchers at Zimperium have identified a sophisticated new Android malware named RatHat, which is reportedly linked to threat actors in China. The malware distinguishes itself by integrating generative artificial intelligence to automate its operations, allowing it to interpret screen content and make autonomous decisions on where to tap, scroll, or click.

RatHat typically infects devices through social engineering, such as phishing SMS messages, malicious advertisements, or fraudulent websites mimicking the Google Play Store. Once installed, the malware requests Android Accessibility Service permissions. With this access, it can activate Developer Options and Wireless Debugging to gain shell-level control via the Android Debug Bridge (ADB).

The malware is capable of significant data theft, including intercepting SMS messages, one-time passwords (OTP), and two-factor authentication (2FA) codes. It can also record screen touches to reconstruct PINs and unlock patterns, and deploy fake login overlays to steal banking and cryptocurrency credentials. Its ability to adapt to different user interfaces makes it more difficult for traditional security software to detect compared to scripted malware.

Entities

Android · China · Google · Google Play Store · Malwarebytes · RatHat · Zimperium

Claims

What the coverage asserts, and how many sources carry each claim.