www.securityweek.com 21 Sept 2026, 12:51 UTC

AI-Powered RatHat Android Trojan Hijacks Devices Through Smishing

AI-Powered RatHat Android Trojan Hijacks Devices Through Smishing

MOBILE security company Zimperium has reported a newly discovered Android trojan, dubbed RatHat, which is distributed through smishing and malvertising. The malware uses a multi-stage infection process intended to escape Android’s application sandbox and obtain shell-level execution. Its capabilities include stealing credentials, impersonating banking and payment applications, intercepting SMS messages, capturing screens and user input, and establishing a covert command-and-control channel for remote access.

RatHat’s distinguishing feature is its use of generative artificial intelligence to read a device’s Accessibility tree, interpret on-screen content and navigate the interface in real time. It can also reconstruct PINs, passwords and screen patterns by monitoring accessibility text changes, browser address bars and raw touchscreen events gathered with Android’s `getevent` tool.

Zimperium says the malware requests Accessibility and Device Admin permissions, can wipe the device, and uses a hidden service to restore itself and its permissions after removal. Its three-part architecture comprises a malicious Android application, a Go-based agent and an FRP reverse-proxy client, which creates a persistent tunnel to the ADB daemon for command execution.

According to Zimperium, RatHat is installed by a dropper carrying two encrypted assets and abusing native SessionInstaller APIs. The malware’s AI prompts suggest development by a Chinese threat actor, although the report does not identify a specific group or confirm exploitation against named victims.

The described persistence and credential-stealing functions mean affected users would need to remove the malware and revoke any granted Accessibility or Device Admin permissions; compromised credentials and accounts should also be treated as exposed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline