bleeping-computer · Crawled Sep 18, 2026

New RatHat Android malware uses AI to automate device control

1 Malware
Read original article ↗

AI Summary

A new Android malware named RatHat has been identified by Zimperium zLabs, which leverages AI to automate remote device navigation and control. The malware is distributed via malvertising, SMS, and phishing sites that prompt users to download malicious APKs outside Google Play. It abuses Android Accessibility permissions and enables Developer Options and Wireless Debugging to establish persistent ADB-level access through a Go-based agent. The malware includes credential harvesting, SMS interception, and lock-screen bypass capabilities, and uses AI to dynamically interpret the device interface for real-time remote control. Anti-analysis techniques and persistence mechanisms make it resilient to removal and detection.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 8 techniques