Tag

Rathat

All articles tagged with #rathat

RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims
cybersecurity7 days ago

RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims

Security researchers have identified RatHat, an Android banking trojan that leverages Google’s Gemini AI to navigate device interfaces and prioritize victims with high bank balances. The malware spreads via SMS phishing and malicious ads, requiring users to sideload apps and grant Accessibility permissions. Once installed, it exploits Wireless Debugging to gain shell-level access, intercepts two-factor authentication codes, and reconstructs PINs by analyzing touch coordinates. Cleafy reports that the malware’s control console uses AI to sort victims by financial value, while Zimperium notes its persistence mechanisms make removal difficult without a factory reset.

RemControl and RatHat: AI-Driven Android Malware Targets Banking Users in Europe and Canada
cybersecurity14 days ago

RemControl and RatHat: AI-Driven Android Malware Targets Banking Users in Europe and Canada

Two new Android malware strains, RemControl and RatHat, are exploiting AI and accessibility permissions to steal banking credentials. RemControl, a malware-as-a-service platform, targets users in Europe and Canada via fake TVTap app downloads, while RatHat uses AI to navigate device interfaces and capture touch inputs for PINs.

RatHat: AI-driven Android malware stealthily seizes device control
technology19 days ago

RatHat: AI-driven Android malware stealthily seizes device control

A new Android malware named RatHat uses AI-powered capabilities to secretly gain admin-level control by masquerading as a legitimate app, abusing accessibility permissions and Wireless Debugging to escalate to ADB Shell, then installing an AI-assisted agent and a proxy to exfiltrate data. It targets popular financial apps (WeChat Pay and Alipay) with 162 infected apps detected so far, and can silently capture screen content, usernames, passwords, 2FA codes, touch input to reproduce PINs and patterns, and SMS messages; removal is difficult because the malware hides files and can reinstall after uninstalling, making a full factory reset the recommended fix. Prevention includes avoiding suspicious links, verifying Play Store authenticity, and denying accessibility permissions; Malwarebytes on Google Play can help detect it.