RatHat: AI-powered Android malware steals bank credentials, resists deletion
New malware discovered by Zimperium uses AI and accessibility permissions to gain admin control, targeting financial apps across 162 infected apps.
What to know
- RatHat exploits Android accessibility permissions to escalate to admin control, then installs an AI agent to steal passwords, PINs, and 2FA codes targeting financial apps.
- Found in 162 infected apps claiming to be legitimate software like Google Chrome; primarily targets Chinese payment apps (WeChat Pay, Alipay) but can compromise other financial apps.
- Factory reset is the only reliable removal method; antivirus detection and uninstallation are insufficient because the malware retains admin access through hidden files and can reinstall itself.
“Unfortunately, because of the behavior of the program itself — remasquerading as other apps, dynamically changing its behavior using the AI endpoint — static analysis and quarantining is not enough to remove the malware.”
Sav Wheeler, Research engineer, Malwarebytes · CNET ↗
Zimperium Mobile security firmSav Wheeler Research engineer, Malwarebytes
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
CNET publishes technical breakdown of RatHat's infection chain and capabilities
CNET details how RatHat requests accessibility permissions, uses them to unlock Wireless Debugging and ADB Shell, then installs an AI-assisted agent to steal data. The malware targets financial apps and has been found in 162 infected apps reporting to a dozen attacker-controlled servers.
“Escalation in the Android landscape often relies on granting apps additional permissions that the OS locks away by default to keep the devices secure.”
— Sav Wheeler, Malwarebytes research engineer -
B
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. https://www. bleepingcomputer.com/news/secu rity/new-rathat-android-malware-uses-ai-to-automate-device-control/
1 more of the top 2 · 2 posts in this stretch
-
P
New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN https:// packetstorm.news/news/view/437 24 # news
-
-
background
Zimperium discovers RatHat, AI-powered Android malware with admin escalation — Mobile security firm Zimperium identified RatHat, which uses AI and exploits Android accessibility permissions to gain admin-level control. The malware mimics legitimate apps like Google Chrome via fake Google Play Store pages.
Also covered reported alongside — the timeline has no entry for these yet
-
first by BleepingComputer, 3d ago · also Inshorts, Malwarebytes, TechRadar
3 more headlines
- New Android malware uses AI to steal bank logins, remains after deletion | Do factory reset if device infected with RatHat | Inshorts Inshorts · 3d ago
- New Android malware uses AI to steal bank logins and PINs Malwarebytes · 3d ago
- New Android malware can deploy AI to automate device control TechRadar · 2d ago
and 3 smaller pieces