< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 24 sources · 4 days · First seen · Last updated

RatHat Android malware deployment

Overview

Security researchers at Zimperium have identified a sophisticated Android Trojan known as RatHat. The malware is distinguished by its integration of generative artificial intelligence, which allows it to interpret screen content in real time—such as buttons, text, and open fields—to automate device navigation and execute autonomous commands.

RatHat typically spreads via smishing, phishing sites, or malicious advertisements that mimic legitimate software. Once a user sideloads the malicious APK, the malware pressures them to enable Android’s Accessibility Services. It further exploits the Android Debug Bridge (ADB) through local self-pairing to bypass app sandboxing and deploy native binaries with elevated shell-level privileges. This enables the malware to maintain persistence on a device, potentially remaining active even after the original application is uninstalled.

The primary objective of the malware is the theft of financial data and credentials. It is capable of intercepting two-factor authentication (2FA) or one-time passwords (OTPs), capturing screen content, and displaying fake login pages for banking and cryptocurrency services. Researchers have linked the operations of this threat to actors based in China.

Recent analysis highlights that RatHat’s ability to adapt to various user interfaces makes it more difficult for traditional security software to detect compared to scripted malware. Beyond intercepting SMS and codes, the malware can record screen touches to reconstruct PINs and unlock patterns.

Entities

Zimperium · Google · RatHat · China · Malwarebytes

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 11 sources
    RatHat malware uses generative AI to target Android devices

    RatHat is a new Android malware using generative AI to autonomously navigate devices, steal sensitive data like banking credentials and 2FA codes, and bypass traditional security measures.

  2. 6 days ago

    [TECHNOLOGY] 13 sources
    RatHat Android malware uses generative AI to steal credentials

    RatHat, a new Android Trojan, uses generative AI to navigate infected devices and steal banking credentials. It exploits ADB and accessibility services to maintain persistence even after uninstallation.

Sources

4gnews.pt · ad-hoc-news.de · albiladpress.com · arenait.net · cybernoz.com · dev.to · futurezone.de · gamemag.it · gateeg.com · gdatasoftware.com · hothardware.com · infoguerra.com.br · ipaddisti.it · it-boltwise.de · ithome.com · labandadiario.com.ar · malwarebytes.org · mashable.com · me.mashable.com · que.com · sea.mashable.com · time.news · todoandroid.es · vosveteit.zoznam.sk

This summary has been updated 1 time: see revision history