Zimperium researchers discovered RatHat, a new Android malware linked to Chinese threat actors that uses generative AI to record screen touches and steal passwords. The malware spreads through fake app downloads, requests accessibility permissions, and leverages Android's Wireless Debugging feature to capture text messages, credentials, and authentication codes.
RatHat is AI-powered malware targeting Android devices that tricks users into downloading fake apps mimicking legitimate software like Google Chrome. It exploits accessibility permissions to gain admin-level control, stealing passwords, authentication codes, and financial app data from victims primarily in China. The malware can only be removed via factory reset and is best avoided by verifying official app sources and avoiding suspicious links.
RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.