conv.

All stories
SecurityFading · day 6

RatHat: AI-powered Android malware steals bank credentials, resists deletion

New malware discovered by Zimperium uses AI and accessibility permissions to gain admin control, targeting financial apps across 162 infected apps.

What to know

  • RatHat exploits Android accessibility permissions to escalate to admin control, then installs an AI agent to steal passwords, PINs, and 2FA codes targeting financial apps.
  • Found in 162 infected apps claiming to be legitimate software like Google Chrome; primarily targets Chinese payment apps (WeChat Pay, Alipay) but can compromise other financial apps.
  • Factory reset is the only reliable removal method; antivirus detection and uninstallation are insufficient because the malware retains admin access through hidden files and can reinstall itself.

“Unfortunately, because of the behavior of the program itself — remasquerading as other apps, dynamically changing its behavior using the AI endpoint — static analysis and quarantining is not enough to remove the malware.”

Sav Wheeler, Research engineer, Malwarebytes · CNET ↗

Zimperium Mobile security firmSav Wheeler Research engineer, Malwarebytes

RatHat: AI-powered Android malware steals bank credentials, resists deletion
CNET

How it unfolded 1 development · click the chart to see its coverage articlesposts

Peak 5 pieces in two hours at Sep 20, 8 AM; 15 pieces over 6 days (9 articles · 6 posts) Sep 17, 4 PM — 2 pieces · 2 posts — Mastodon 2Sep 17, 6 PM — quietSep 17, 8 PM — quietSep 17, 10 PM — quietSep 18, 12 AM — quietSep 18, 2 AM — quietSep 18, 4 AM — quietSep 18, 6 AM — quietSep 18, 8 AM — quietSep 18, 10 AM — quietSep 18, 12 PM — quietSep 18, 2 PM — quietSep 18, 4 PM — quietSep 18, 6 PM — quietSep 18, 8 PM — quietSep 18, 10 PM — quietSep 19, 12 AM — quietSep 19, 2 AM — quietSep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — quietSep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — 5 pieces · 5 articles — Google News 4, Newswires 1Sep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — 1 piece · 1 post — Mastodon 1Sep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — 1 piece · 1 article — Newswires 1Sep 21, 8 AM — 1 piece · 1 post — Mastodon 1Sep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — quietSep 21, 4 PM — 1 piece · 1 post — Mastodon 1Sep 21, 6 PM — 3 pieces · 3 articles — Google News 2, Newswires 1Sep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — 1 piece · 1 post — Hacker News 1Yesterday, 8 PM — quietYesterday, 10 PM — quietToday, 12 AM — quiet 1
Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 2:55 AM ET
  1. 1

    CNET publishes technical breakdown of RatHat's infection chain and capabilities

    CNET details how RatHat requests accessibility permissions, uses them to unlock Wireless Debugging and ADB Shell, then installs an AI-assisted agent to steal data. The malware targets financial apps and has been found in 162 infected apps reporting to a dozen attacker-controlled servers.

    “Escalation in the Android landscape often relies on granting apps additional permissions that the OS locks away by default to keep the devices secure.”
    — Sav Wheeler, Malwarebytes research engineer
    • BleepingComputer@infosec.exchange

      A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. https://www. bleepingcomputer.com/news/secu rity/new-rathat-android-malware-uses-ai-to-automate-device-control/

      BleepingComputer@infosec.exchangeMastodon6d agoview on Mastodon ↗
    1 more of the top 2 · 2 posts in this stretch
    • packet_storm@infosec.exchange

      New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN https:// packetstorm.news/news/view/437 24 # news

      packet_storm@infosec.exchangeMastodon2d agoview on Mastodon ↗
    all of them →
  2. background

    Zimperium discovers RatHat, AI-powered Android malware with admin escalation — Mobile security firm Zimperium identified RatHat, which uses AI and exploits Android accessibility permissions to gain admin-level control. The malware mimics legitimate apps like Google Chrome via fake Google Play Store pages.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by BleepingComputer, 3d ago · also Inshorts, Malwarebytes, TechRadar

    3 more headlines

and 3 smaller pieces

What people are saying 0 voices from 0 sites · best of 2 · verbatim