www.infosecurity-magazine.com 17 Sept 2026, 13:00 UTC

New RatHat Android Malware Uses AI to Steal Banking Data and OTPs

New RatHat Android Malware Uses AI to Steal Banking Data and OTPs

SECURITY researchers at Zimperium have identified a new Android malware strain called RatHat, which targets credentials and financial information. The researchers link the campaign to threat actors that appear to be operating in China. RatHat is distributed through malvertising, SMS phishing and third-party forums, which direct victims to deceptive sites and malicious APKs posing as legitimate applications.

A dropper installs the malware from two encrypted assets, using native SessionInstaller APIs to bypass Android restrictions around unknown applications and Accessibility Services. RatHat includes four anti-analysis layers and one anti-debugging layer. Its malicious app can collect banking credentials, notifications, two-factor authentication and one-time-password data, as well as capture screens and user input.

Zimperium’s zLabs team also found a generative-AI interface-automation engine that serialises the device’s live Accessibility tree into XML and communicates in Mandarin with an unidentified AI assistant. The researchers said the system can identify screen coordinates, read on-screen text and issue navigation commands; a graph suggested Google Gemini models may have been used, although the specific tool was not named.

RatHat’s Go agent, `liblocal-service.so`, executes privileged commands through the local Android Debug Bridge shell, including changing battery-optimisation settings and disabling or removing other packages. Its FRP client, `libmedia_codec.so`, creates a persistent reverse tunnel to the attackers’ command-and-control server, providing ongoing ADB access and the ability to run arbitrary commands. Zimperium published its analysis on 16 September 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline