AI-powered RatHat malware hijacks Android devices with remote UI control

1 min read
Source: BleepingComputer
AI-powered RatHat malware hijacks Android devices with remote UI control
Photo: BleepingComputer
TL;DR Summary

A new Android malware named RatHat uses an AI-powered UI automation subsystem to remotely control compromised devices via Accessibility permissions, enabling actions such as enabling Developer Options, ADB shell access, keylogging, credential-stealing overlays, SMS/OTP interception, and a persistent reverse-proxy tunnel; it can restore itself after removal and even intercept uninstall prompts. Linked to Chinese actors per Zimperium, RatHat spreads via malvertising, phishing, and APKs from outside Google Play, and includes anti-analysis tricks to hinder detection. Users are advised to avoid sideloaded APKs, revoke unnecessary Accessibility permissions, and regularly scan with Play Protect.

Share this article

Reading Insights

Total Reads

1

Unique Readers

6

Time Saved

3 min

vs 4 min read

Condensed

88%

75992 words

Want the full story? Read the original article

Read on BleepingComputer