www.malwarebytes.com 21 Sept 2026, 07:02 UTC

Android RatHat Malware Steals Bank Logins and Screen-Lock PINs

Android RatHat Malware Steals Bank Logins and Screen-Lock PINs
CyberSIXT Evidence Panel Source marked as original reporting

MALWAREBYTES’ weekly roundup for 14–20 September 2026 highlighted several cybersecurity and privacy stories, but provided only brief descriptions rather than full reports. Topics included RatHat, an Android malware strain reportedly able to navigate infected phones while stealing bank logins, authentication codes and screen-lock PINs; phishing campaigns impersonating parcel services, Revolut and T-Mobile; and fake Bitrefill checkout pages appearing in search results.

The roundup also covered a modem flaw reportedly being actively exploited against Google Pixel devices, an HBO Max Reddit account hijacked to distribute malware, and AI-generated antivirus renewal pages used by scammers.

Other items concerned Flock camera systems tracking people as well as vehicles, Meta AI creating detailed profiles of children from family posts, Google search redirects making destinations harder to inspect, celebrity deepfake websites seized by the Manhattan district attorney, and Revolut disclosing customer IDs and financial information to an impostor claiming to represent a government body.

The article supplies no CVE numbers, affected-version details, victim figures or mitigation instructions, and the roundup itself does not provide enough evidence to assess the individual incidents beyond these summaries.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline