Security News

Cybersecurity news aggregator

🤖
HIGH Attacks Zimperium

RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts

RatHat is a novel Android malware distributed via targeted smishing and malvertising that uses an automated, multi-stage infection pipeline to gain persistent, high-privilege access. It uniquely leverages AI for real-time device control and employs hardware-level touch monitoring to steal credentials, while its self-restoring background service ensures persistence even after the main app is uninstalled.
Read Full Article →

Executive Summary The zLabs team has uncovered RatHat , a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline. Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges. Key Technical Findings Global Financial Targeting: The malware deploys sophisticated, fake interfaces designed to mimic legitimate banking and payment apps, tricking users into providing their financial login credentials, while also intercepting OTP/2FA codes. AI-Driven Automation: RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation. Hardware-Level Credential Theft: By monitoring raw touch input at the hardware level, the malware bypasses standard security protections, allowing it to reconstruct PINs, passwords, and unlock patterns by tracking finger movements directly. Self-Escalating Privileges: The malware automatically grants itself deep, administrative-level control over the device without needing a host computer, enabling unrestricted access to critical system functions. Persistent & Self-Restoring Access: The malware installs a hidden background service that operates independently of the main app. If a user uninstalls the app, this service remains active, silently reinstalling the malware and restoring its malicious permissions. Stealthy Communication Channels: It establishes a covert, permanent connection to the attacker's server, bypassing network security measures to maintain continuous, unauthorized remote control. RatHat highlights a distinct paradigm shift in the mobile threat landscape: moving away from static, easily disrupted automation toward adaptive, AI-assisted execution chains that operate outside the constraints of traditional mobile app sandboxes.

Share this article