< Back to situation

[REVISION HISTORY]

RatHat Android malware deployment

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-21 02:21 UTC → 2026-09-22 06:52 UTC · added removed

Security researchers at Zimperium have identified a sophisticated Android Trojan known as RatHat. The malware is distinguished by its integration of generative artificial intelligence, which allows it to interpret screen content in real time—such as buttons, text, and open fields—to automate device navigation and execute autonomous commands. RatHat typically spreads via smishing, phishing sites, or malicious advertisements that mimic legitimate software. Once a user sideloads the malicious APK, the malware pressures them to enable Android’s Accessibility Services. It further exploits the Android Debug Bridge (ADB) through local self-pairing to bypass app sandboxing and deploy native binaries with elevated shell-level privileges. This enables the malware to maintain persistence on a device, potentially remaining active even after the original application is uninstalled. The primary objective of the malware is the theft of financial data and credentials. It is capable of intercepting two-factor authentication (2FA) or one-time passwords (OTPs), capturing screen content, and displaying fake login pages for banking and cryptocurrency services. Researchers have linked the operations of this threat to actors based in China. Recent analysis highlights that RatHat’s ability to adapt to various user interfaces makes it more difficult for traditional security software to detect compared to scripted malware. Beyond intercepting SMS and codes, the malware can record screen touches to reconstruct PINs and unlock patterns.

Versions

  1. 2026-09-22 06:52 UTC RatHat Android malware deployment
  2. 2026-09-21 02:21 UTC RatHat Android malware deployment

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.