RatHat: AI-driven Android malware stealthily seizes device control

A new Android malware named RatHat uses AI-powered capabilities to secretly gain admin-level control by masquerading as a legitimate app, abusing accessibility permissions and Wireless Debugging to escalate to ADB Shell, then installing an AI-assisted agent and a proxy to exfiltrate data. It targets popular financial apps (WeChat Pay and Alipay) with 162 infected apps detected so far, and can silently capture screen content, usernames, passwords, 2FA codes, touch input to reproduce PINs and patterns, and SMS messages; removal is difficult because the malware hides files and can reinstall after uninstalling, making a full factory reset the recommended fix. Prevention includes avoiding suspicious links, verifying Play Store authenticity, and denying accessibility permissions; Malwarebytes on Google Play can help detect it.
- Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem CNET
- RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts Zimperium
- New Android malware uses AI to steal bank logins and PINs Malwarebytes
- RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall The Hacker News
- New Android malware uses AI to steal bank logins, remains after deletion | Do factory reset if device infected with RatHat | Inshorts inshorts.com
Want the full story? Read the original reporting
Read on CNET