New RatHat Android malware uses AI to automate device control

New RatHat Android malware uses AI to automate device control
RatHat is a new Android malware that uses an AI-powered subsystem to help attackers remotely navigate infected devices and steal sensitive data. Zimperium links it to Chinese threat actors and notes that it is distributed through malvertising, SMS, and phishing sites that push APK downloads outside Google Play. #RatHat #Zimperium

Keypoints

  • RatHat abuses Android Accessibility permissions to gain powerful control over infected devices.
  • It enables Developer Options and Wireless Debugging to obtain shell-level access without an external computer.
  • The malware installs Go-based agents for ADB command execution, persistence, and reverse-proxy tunneling.
  • RatHat uses fake overlays to steal banking credentials, SMS codes, PINs, passwords, and unlock patterns.
  • Its AI-driven interface automation helps operators remotely navigate devices and evade detection.

Read More: https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/