New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.

Zimperium zLabs researchers analyzed the malware and believe it is linked to threat actors from China after finding it using LLM prompts written in Chinese.

The researchers say the malware is distributed through malvertising, SMS, and phishing sites promoting APK downloads from outside Google Play.

Like most Android malware families, RatHat relies on abusing Android’s Accessibility permissions to perform highly privileged actions on infected devices.

Most notably, it enables Developer Options and Wireless Debugging to gain a local shell-level execution context without requiring an external computer, similarly to mechanisms seen in the ToxicPanda and RedHook Android malware families.

ADB access lets RatHat install a Go-based agent (liblocal-service.so) that runs commands with ADB shell privileges, creates battery-restriction bypasses, and manages persistence.

The same agent also restores the malware if it’s removed or stopped, providing a persistence channel independent of the malware itself. This back-up goes both ways, with the malware restoring the agent if it’s removed.

A second agent (libmedia_codec.so) also acts as an FRP reverse-proxy client, establishing a persistent tunnel to the attacker.

The malware displays HTML overlays for targeted banking and cryptocurrency applications to capture account credentials.

It can also intercept SMS messages and notifications, including one-time passwords; record text-change events; extract URLs from browser address bars; and capture lock-screen PINs, passwords, and unlock patterns.

Zimperium reports that RatHat uses an AI-powered user interface-automation engine that serializes the live Android Accessibility tree into XML and sends it to a popular AI assistant not named in the report.

This AI-powered subsystem makes RatHat’s interface automation more adaptable than automation based entirely on fixed scripts, allowing remote navigation without requiring the operators to perform real-time interaction.

“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation,” comments Zimperium.

The researchers warn that RatHat will actively thwart removal attempts by intercepting the uninstall confirmation screen, canceling the procedure, and displaying a fake Google Play overlay containing a bogus error message.

Zimperium also highlights multiple anti-analysis techniques embedded in the malware, including APK container tampering, a bloated (61MB) Android manifest file, and invalid DEX pseudo instructions, all aimed at confusing or breaking analysis tools.

Android users should never download APK files from outside Google Play unless they explicitly trust the publisher, avoid granting Accessibility permissions to apps, and regularly scan their devices with Play Protect.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

ToxicPanda Android malware uses VPN permissions to block Google Play

New Manic Android malware can exfiltrate data through nearby devices

OpenAI details more cases of AI agents taking unauthorized actions

Anthropic wants Claude to analyze your bank account and financial data

Spain’s data agency gets first report of AI-powered data breach

RedHat is evil. Ha! Works both ways. On topic this is just a MITM attack with extra steps. It would be sad to see if ADB gets nerfed due to this incident because a malicious DNS/VPN app could replicate most of this malware.

Gyazo server flaw exploited to steal 23.6 million user records

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.