
AI-powered RatHat malware hijacks Android devices with remote UI control
A new Android malware named RatHat uses an AI-powered UI automation subsystem to remotely control compromised devices via Accessibility permissions, enabling actions such as enabling Developer Options, ADB shell access, keylogging, credential-stealing overlays, SMS/OTP interception, and a persistent reverse-proxy tunnel; it can restore itself after removal and even intercept uninstall prompts. Linked to Chinese actors per Zimperium, RatHat spreads via malvertising, phishing, and APKs from outside Google Play, and includes anti-analysis tricks to hinder detection. Users are advised to avoid sideloaded APKs, revoke unnecessary Accessibility permissions, and regularly scan with Play Protect.












