Skip to content
Tech News
← Back to articles

Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem

read original get Bitdefender Mobile Security for Android → more articles
Why This Matters

RatHat represents a new class of AI-assisted Android malware that tricks users into granting accessibility and debugging permissions, then quietly gains full admin control of the device to steal financial data. Its stealthy, patient approach and use of AI to automate system commands make it harder to detect than typical malware, raising the stakes for mobile security across the Android ecosystem.

Key Takeaways
Worth a Look

Bitdefender Mobile Security for Android — With sophisticated malware like RatHat exploiting accessibility permissions to hijack Android devices, having a dedicated mobile security app that scans installed apps and blocks malicious downloads is a smart line of defense. Bitdefender Mobile Security actively monitors app behavior and flags suspicious permission requests, helping you avoid fake Play Store lookalikes before they gain a foothold.

See Bitdefender Mobile Security for Android on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

There’s a frightening new digital threat that Android users should be aware of. New AI-powered malware called RatHat can automatically gain admin-level control over your Android device, stealing whatever it wants.

RatHat was discovered by mobile security firm Zimperium, which notes that the program tricks people into downloading what appears to be a legitimate app, such as Google Chrome, via a fake web page that mimics the Google Play Store. Once opened, the app seemingly innocently asks for accessibility permissions, which it then uses to take over your entire device.

RatHat uses the accessibility permissions users grant it to navigate your phone’s menu system and unlock Wireless Debugging, a legitimate developer tool commonly used in app testing, then grants itself ADB Shell permissions. This effectively grants the malware admin access to your device. Next, RatHat installs an AI-assisted agent that runs system commands to steal information and a proxy client that tunnels that stolen information back to the hacker.

“That sort of infection chain isn’t necessarily more complex than, say, following a phishing email on Windows and saying yes when the program asks for administrator permissions,” Sav Wheeler, a research engineer for Malwarebytes, said in an email. “Escalation in the Android landscape often relies on granting apps additional permissions that the OS locks away by default to keep the devices secure.”

Per Zimperium, the malware can be traced to attackers in China and primarily targets apps like WeChat Pay and Alipay, which are as popular in China as Apple Pay and Venmo are in the US. Malwarebytes notes that other financial apps can also be targeted. So far, researchers have found 162 infected apps in the wild, which report back to a dozen servers run by attackers.

What can this malware do?

The worrisome part is that the malware doesn’t do anything wonky the user would notice immediately, unlike with a ransomware attack. Instead, it bides its time, runs in the background, and captures information that appears on the screen, including usernames, passwords and two-factor authentication codes.

It can also steal raw touch input from your touchscreen, allowing it to recreate PIN codes and pattern unlock codes. It can capture SMS messages, too, thereby intercepting security codes. There isn’t much that the app can’t steal if it wants to.

How can I find out if I have RatHat on my phone?

The only way to find it is to run an antivirus scan that detects the software. Malwarebytes is a free option on Google Play that can do this. Wheeler told CNET that it can detect the malware pretty easily, which is good news for anyone who’s worried about whether or not they have it.

... continue reading