Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Shop Sandisk to save up to $92

    September 18, 2026

    The good news is that Samsung Gallery is now getting Google Photos integration

    September 18, 2026

    We know pretty much everything about the OnePlus 16 now

    September 18, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Friday, September 18
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Android»New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
    Android

    New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

    myappsplusBy myappsplusSeptember 18, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.

    The malware, named RatHat by the researchers, is linked to threat actors that appear to be operating in China.

    It incorporates novel techniques for persistence and leverages generative AI for operational control.

    RatHat’s Delivery: Smishing, Malvertising and Malicious App

    RatHat is primarily distributed through deceptive phishing sites promoted campaigns and third-party forums

    The threat actors behind the malicious campaign use these channels to lure victims into manually downloading malicious Android package kits (APKs) that appear to be legitimate apps.

    Once deployed, the malicious app deploys RatHat

    The dropper exploits native SessionInstaller APIs to bypass Android’s restricted settings and Accessibility Service protections, enabling the installation of the malicious payload and subsequent access to protected APIs.

    The malware also contains four anti-analysis layers and one anti-debug layer to bypass Android’s security controls.

    RatHat’s Architecture Explained

    The architecture of the RatHat malware can be broken down into three primary operational parts:

    • Malicious Android application
    • Go agent (liblocal-service.so)
    • FRP client (libmedia_codec.so)

    The app’s main role is to act as the primary interface with the user, acquire critical system permissions and bootstrap the rest of the infection chain.

    The app carries spyware capabilities, with the capacity to collect banking credentials, notifications, two-factor authentication (2FA) and one-time-password (OTP) keys, and capture screen and inputs.

    In a malware analysis published on September 16, Zimperium’s zLabs team noted a particularly interesting feature in the malicious app: a generative AI user interface-automation engine.

    In practice, RatHat serializes the target device’s live Accessibility tree to XML and communicates in Mandarin with “one of the world’s most popular generative AI assistants,” the researchers noted.

    This AI tool is used for non-malicious actions including:

    • Resolving a named target’s centre coordinates on the screen as JSON to direct synthetic clicks
    • Resolving a target’s actual on-screen text from the XML (without translating)
    • Signaling automatic navigation commands like SCROLL_DOWN

    While the researchers did not specify which AI tool is used in the report, they provided a graph suggesting the threat actors used Google’s Gemini AI models.

    RatHat's architecture and operational flow. Source: Zimperium
    RatHat’s architecture and operational flow. Source: Zimperium

    The prompts used by RatHat operators in the zLabs investigation are the main indicator of potential China-based threat actors.

    The Go agent is the privileged command-and-control (C2) executor that runs commands through the local ADB shell context to bypass app-level security restrictions.

    It handles critical system-level tasks like exempting the app from battery optimization/Doze mode, prioritizing its background execution and disabling or uninstalling other packages (like security apps), while also fetching the FRP client’s configuration from the C2 server.

    Finally, the FRP client establishes a persistent, secure reverse tunnel from the infected device back to the attacker’s C2 server. Its sole purpose is to give attackers ongoing remote access to the device’s ADB daemon, acting as a general-purpose backdoor that can carry arbitrary commands independent of the malware’s built-in features.

    “RatHat’s multi-tiered architecture, reliance on out-of-lifecycle daemons, and use of real-time GenAI decision loops illustrate why traditional, signature-based mobile security controls are insufficient,” the zLabs report noted.

    Android Leverages malware RatHat Steal
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    We know pretty much everything about the OnePlus 16 now

    September 18, 2026

    Survey says loads of Google Messages users aren’t keen on this incoming feature

    September 18, 2026

    Your smartwatch is probably good enough, and the market knows it

    September 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20263 Views

    Top 10 Best React Native App Development Companies in 2026

    September 12, 20262 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views
    Latest Reviews

    Apple may have accidentally teased its own roadmap with 14 unreleased devices revealed — but this long overdue update has me most excited

    myappsplusAugust 19, 2026

    Apple TV 4K fans are begging for these 3 upgrades from the leaked Siri Remote — but one is already possible today

    myappsplusAugust 20, 2026

    Can MainstreamOS finally make Linux a household name? I tried it to find out

    myappsplusAugust 20, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Apple may have accidentally teased its own roadmap with 14 unreleased devices revealed — but this long overdue update has me most excited

    August 19, 20260 Views

    Apple TV 4K fans are begging for these 3 upgrades from the leaked Siri Remote — but one is already possible today

    August 20, 20260 Views

    Can MainstreamOS finally make Linux a household name? I tried it to find out

    August 20, 20260 Views
    Our Picks

    Shop Sandisk to save up to $92

    September 18, 2026

    The good news is that Samsung Gallery is now getting Google Photos integration

    September 18, 2026

    We know pretty much everything about the OnePlus 16 now

    September 18, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.