RatHat Uses Android Accessibility as Control Surface
Zimperium found a new Android spyware and backdoor strain called RatHat, distributed through smishing, malvertising, and forums to harvest banking data, notifications, one-time passwords, and screen input. The campaign uses deceptive app installers that look legitimate to get victims to sideload the malware.
RatHat serializes the phone’s live Accessibility tree and sends it to a generative AI service so the operator can ask what is on screen or where to click next. That lets the malware steer the device in real time instead of following fixed taps, which makes it better at stealing OTPs and login data even when the user has to approve the install themselves.
For organizations with Android users on personal devices, the exposure sits in the approval and banking flow, not just on managed endpoints. Static detections that expect one script or one payload path may miss a campaign that changes its actions on-device as the screen changes.
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.