# RatHat Android malware deployment

> Live situation record from CLSTR: https://clstr.news/situations/rathat-android-malware-deployment
> Updated: 2026-09-20T18:53:31.000Z. Sources: 24. Developments: 2.

Security researchers at Zimperium have identified a sophisticated Android Trojan known as RatHat. The malware is distinguished by its integration of generative artificial intelligence, which allows it to interpret screen content in real time—such as buttons, text, and open fields—to automate device navigation and execute autonomous commands.

RatHat typically spreads via smishing, phishing sites, or malicious advertisements that mimic legitimate software. Once a user sideloads the malicious APK, the malware pressures them to enable Android’s Accessibility Services. It further exploits the Android Debug Bridge (ADB) through local self-pairing to bypass app sandboxing and deploy native binaries with elevated shell-level privileges. This enables the malware to maintain persistence on a device, potentially remaining active even after the original application is uninstalled.

The primary objective of the malware is the theft of financial data and credentials. It is capable of intercepting two-factor authentication (2FA) or one-time passwords (OTPs), capturing screen content, and displaying fake login pages for banking and cryptocurrency services. Researchers have linked the operations of this threat to actors based in China. 

Recent analysis highlights that RatHat’s ability to adapt to various user interfaces makes it more difficult for traditional security software to detect compared to scripted malware. Beyond intercepting SMS and codes, the malware can record screen touches to reconstruct PINs and unlock patterns.

## Claims

- RatHat is a new Android malware strain discovered by Zimperium researchers. (corroborated by 9 sources)
- The malware uses generative AI to interpret screen content and make autonomous navigation decisions. (corroborated by 9 sources)
- RatHat exploits Android Accessibility Services to gain control. (corroborated by 8 sources)
- The malware can activate Wireless Debugging to gain shell-level access via ADB. (corroborated by 8 sources)
- RatHat can intercept SMS, OTP codes, and two-factor authentication (2FA) data. (corroborated by 8 sources)
- The malware spreads via phishing SMS, malicious ads, and fake Google Play Store pages. (corroborated by 7 sources)
- RatHat is linked to threat actors based in China. (corroborated by 5 sources)
- The malware can record screen touches to reconstruct PINs and unlock patterns. (corroborated by 4 sources)

## Timeline

### 2026-09-20: RatHat malware uses generative AI to target Android devices

RatHat is a new Android malware using generative AI to autonomously navigate devices, steal sensitive data like banking credentials and 2FA codes, and bypass traditional security measures.

11 sources. https://clstr.news/cluster/rathat-malware-uses-generative-ai-to-target-android-users

### 2026-09-17: RatHat Android malware uses generative AI to steal credentials

RatHat, a new Android Trojan, uses generative AI to navigate infected devices and steal banking credentials. It exploits ADB and accessibility services to maintain persistence even after uninstallation.

13 sources. https://clstr.news/cluster/cybersecurity-researchers-identify-kremlin-and-rathat-malware

---
Cite as: RatHat Android malware deployment. CLSTR, https://clstr.news/situations/rathat-android-malware-deployment
