RatHat is a new Android trojan that uses generative AI to better control infected devices, steal credentials, and maintain persistence through a multi-stage infection chain. Zimperium says the malware likely came from a Chinese threat actor and combines fake app overlays, shell access, and reverse tunnels to enable full device takeover. #RatHat #Zimperium #ADB #frpc
Keypoints
- RatHat spreads through smishing and malvertising.
- It uses a multi-stage chain to escape Android sandboxing and gain shell access.
- The malware leverages generative AI to navigate device interfaces in real time.
- It steals credentials, intercepts SMS, and recreates PINs and passwords through keylogging.
- RatHat can reinstall itself, bypass removal, and keep persistent access through Go and frpc components.
Read More: https://www.securityweek.com/rathat-android-trojan-uses-ai-for-automation/