Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 24 sources · 4 days · First seen · Last updated
RatHat Android malware deployment
Overview
Security researchers at Zimperium have identified a sophisticated Android Trojan known as RatHat. The malware is distinguished by its integration of generative artificial intelligence, which allows it to interpret screen content in real time—such as buttons, text, and open fields—to automate device navigation and execute autonomous commands.
RatHat typically spreads via smishing, phishing sites, or malicious advertisements that mimic legitimate software. Once a user sideloads the malicious APK, the malware pressures them to enable Android’s Accessibility Services. It further exploits the Android Debug Bridge (ADB) through local self-pairing to bypass app sandboxing and deploy native binaries with elevated shell-level privileges. This enables the malware to maintain persistence on a device, potentially remaining active even after the original application is uninstalled.
The primary objective of the malware is the theft of financial data and credentials. It is capable of intercepting two-factor authentication (2FA) or one-time passwords (OTPs), capturing screen content, and displaying fake login pages for banking and cryptocurrency services. Researchers have linked the operations of this threat to actors based in China.
Recent analysis highlights that RatHat’s ability to adapt to various user interfaces makes it more difficult for traditional security software to detect compared to scripted malware. Beyond intercepting SMS and codes, the malware can record screen touches to reconstruct PINs and unlock patterns.
Entities
Zimperium · Google · RatHat · China · Malwarebytes
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] RatHat is a new Android malware strain discovered by Zimperium researchers. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · que.com · +4 more
- [● 9 SOURCES] The malware uses generative AI to interpret screen content and make autonomous navigation decisions. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · que.com · +4 more
- [● 8 SOURCES] RatHat exploits Android Accessibility Services to gain control. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 8 SOURCES] The malware can activate Wireless Debugging to gain shell-level access via ADB. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 8 SOURCES] RatHat can intercept SMS, OTP codes, and two-factor authentication (2FA) data. gateeg.com · arenait.ro · ipaddisti.it · www.it-boltwise.de · me.mashable.com · +3 more
- [● 7 SOURCES] The malware spreads via phishing SMS, malicious ads, and fake Google Play Store pages. gateeg.com · arenait.ro · ipaddisti.it · me.mashable.com · sea.mashable.com · +2 more
- [● 5 SOURCES] RatHat is linked to threat actors based in China. arenait.ro · me.mashable.com · sea.mashable.com · time.news · mashable.com
- [● 4 SOURCES] The malware can record screen touches to reconstruct PINs and unlock patterns. ipaddisti.it · me.mashable.com · sea.mashable.com · mashable.com
Timeline
-
3 days ago
[TECHNOLOGY] 11 sourcesRatHat malware uses generative AI to target Android devicesRatHat is a new Android malware using generative AI to autonomously navigate devices, steal sensitive data like banking credentials and 2FA codes, and bypass traditional security measures.
-
6 days ago
[TECHNOLOGY] 13 sourcesRatHat Android malware uses generative AI to steal credentialsRatHat, a new Android Trojan, uses generative AI to navigate infected devices and steal banking credentials. It exploits ADB and accessibility services to maintain persistence even after uninstallation.
Sources
4gnews.pt · ad-hoc-news.de · albiladpress.com · arenait.net · cybernoz.com · dev.to · futurezone.de · gamemag.it · gateeg.com · gdatasoftware.com · hothardware.com · infoguerra.com.br · ipaddisti.it · it-boltwise.de · ithome.com · labandadiario.com.ar · malwarebytes.org · mashable.com · me.mashable.com · que.com · sea.mashable.com · time.news · todoandroid.es · vosveteit.zoznam.sk
This summary has been updated 1 time: see revision history