RemControl and RatHat: AI-Driven Android Malware Targets Banking Users in Europe and Canada

Two new Android malware strains, RemControl and RatHat, are exploiting AI and accessibility permissions to steal banking credentials. RemControl, a malware-as-a-service platform, targets users in Europe and Canada via fake TVTap app downloads, while RatHat uses AI to navigate device interfaces and capture touch inputs for PINs.
Key points
- RemControl is a new Android banking trojan distributed via fake Google Play pages impersonating the TVTap IPTV app, targeting users in Italy, France, Spain, Poland, Portugal, Canada, and the Middle East.
- The malware uses a VPN service to block Google Play Protect and requests Accessibility Service permissions to display full-screen phishing overlays, steal credentials, and capture pattern-lock coordinates.
- RatHat is a separate Android trojan that uses a live AI assistant to navigate the device's accessibility tree, allowing it to tap and scroll dynamically rather than following hardcoded scripts.
- RatHat abuses Android Debug Bridge (ADB) and Wireless Debugging to gain shell-level access, enabling it to record raw touch coordinates to reconstruct PINs and unlock patterns.
- Both threats rely on social engineering and malvertising to trick users into sideloading malicious APKs, with RemControl's infrastructure showing signs of AI-assisted development and Russian-language code comments.
Background
Recent Android malware trends have seen a shift toward more sophisticated evasion techniques. In September 2026, Mantax Otax emerged as a hybrid ransomware-spyware strain targeting older Android devices, using Accessibility permissions and GitHub for C2 communication. This follows a pattern of malware abusing legitimate Android features, such as Accessibility Services and VPN permissions, to bypass security checks like Play Protect. The current threats, RemControl and RatHat, represent an evolution in this trend, incorporating AI-driven decision-making and more complex infection chains to evade detection and maintain persistence.
How outlets are covering it
BleepingComputer and Group-IB focus on RemControl, highlighting its MaaS nature, AI-assisted development, and targeting of European and Canadian banking users. Malwarebytes and Mashable emphasize RatHat, noting its use of AI for real-time device control and its ability to capture touch inputs for PINs. While both threats use Accessibility permissions, RemControl relies on phishing overlays and VPN-based Play Protect blocking, whereas RatHat uses ADB and Wireless Debugging for self-escalation. Group-IB attributes RemControl to a Russian-speaking developer, while Zimperium links RatHat to Chinese threat actors.
Why it matters
The rise of AI-driven Android malware poses a significant threat to mobile users, particularly those in Europe and Canada. These threats can steal banking credentials, PINs, and MFA codes, leading to financial losses and identity theft. The use of AI to navigate device interfaces makes these malware strains harder to detect and remove, often requiring a factory reset. Users must be vigilant about downloading apps only from trusted sources and denying unnecessary Accessibility permissions.
What to watch
Security researchers and vendors are likely to update their detection signatures to identify RemControl and RatHat. Users should monitor for suspicious Accessibility permission requests and avoid sideloading APKs from untrusted sources. Further analysis may reveal more about the operators behind these threats, potentially leading to takedowns of their infrastructure. The use of AI in malware development may also prompt a broader discussion on the security implications of AI in the cyber threat landscape.
- New RemControl Android banking malware targets users in Europe and Canada BleepingComputer
- New Android malware uses AI to steal bank logins and PINs Malwarebytes
- RemControl: AI Built the Overlays. Victims Lose their PINs Group-IB
- RatHat is a new Android malware that records your screen touches to steal passwords Mashable
- RatHat Malware Can Hijack Your Android by Disguising Itself as a Legitimate App CNET
Want the full story? Read the original reporting
Read on BleepingComputer