RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.
Hackers compromised HBO Max's verified Reddit account and posted 108 malicious ads using ClickFix social engineering to distribute information-stealing malware to Windows and macOS users. The campaign, linked to a broader operation called PasteSwitch, tricked victims into pasting commands into their terminals to install fake applications, including counterfeit HBO Max apps and cryptocurrency wallets.
Mantax Otax is a new Android malware combining ransomware and spyware capabilities that encrypts files on older Android devices, steals sensitive data including credentials and messages, and harasses victims through pop-ups and intimidation tactics. Indonesian operators distribute it via malicious APKs outside Google Play using phishing and social engineering, with the malware abusing Accessibility services to gain extensive device control and communicating with C2 infrastructure hosted on GitHub and Firebase.