Malware · 11h ago
Zimperium found a new Android spyware and backdoor strain called RatHat, distributed through smishing, malvertising, and forums to harvest banking data, notifications, one-time passwords, and screen input. The campaign uses deceptive app installers that look legitimate to get victims to sideload the malware.
RatHat serializes the phone’s live Accessibility tree and sends it to a generative AI service so the operator can ask what is on screen or where to click next. That lets the malware steer the device in real time instead of following fixed taps, which makes it better at stealing OTPs and login data even when the user has to approve the install themselves.
For organizations with Android users on personal devices, the exposure sits in the approval and banking flow, not just on managed endpoints. Static detections that expect one script or one payload path may miss a campaign that changes its actions on-device as the screen changes.
4 sources covering this story
RatHat Android Trojan Uses AI for Automation
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion.
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
RatHat Android malware abuses Accessibility and ADB pairing to gain shell access and retain control after uninstall.
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
Part of the PlainSec briefing for 2026-09-21