Malware · 11h ago

RatHat Uses Android Accessibility as Control Surface

Zimperium found a new Android spyware and backdoor strain called RatHat, distributed through smishing, malvertising, and forums to harvest banking data, notifications, one-time passwords, and screen input. The campaign uses deceptive app installers that look legitimate to get victims to sideload the malware.

RatHat serializes the phone’s live Accessibility tree and sends it to a generative AI service so the operator can ask what is on screen or where to click next. That lets the malware steer the device in real time instead of following fixed taps, which makes it better at stealing OTPs and login data even when the user has to approve the install themselves.

For organizations with Android users on personal devices, the exposure sits in the approval and banking flow, not just on managed endpoints. Static detections that expect one script or one payload path may miss a campaign that changes its actions on-device as the screen changes.

Timeline

Sources

4 sources covering this story

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories