New Android Malware RatHat Exploits AI for Credential and Banking Theft
Security researchers at Zimperium have uncovered RatHat, a sophisticated Android malware strain designed to harvest banking credentials, two-factor authentication (2FA) codes, and one-time passwords (OTPs). Linked to threat actors operating in China, RatHat employs advanced techniques for persistence, evasion, and operational control including the use of generative AI.
Distribution and Infection Chain
RatHat spreads through multiple deceptive channels, including:
- Smishing (SMS phishing) campaigns
- Malvertising (malicious ads)
- Third-party forums promoting fake apps
Victims are tricked into downloading malicious Android package kits (APKs) disguised as legitimate applications. Once installed, the malware deploys a dropper that bypasses Android’s security protections such as restricted settings and Accessibility Service controls using native SessionInstaller APIs. The payload is delivered in two encrypted assets, and the malware includes four anti-analysis layers and one anti-debug layer to evade detection.
Malware Architecture and Capabilities
RatHat’s structure consists of three key components:
- Malicious Android app – Acts as the user interface, requests critical permissions, and initiates the infection.
- Go agent (liblocal-service.so) – Facilitates core malicious functions.
- FRP client (libmedia_codec.so) – Likely used for remote control or data exfiltration.
The malware’s spyware capabilities include:
- Stealing banking credentials and notifications
- Capturing 2FA/OTP codes
- Logging screen activity and user inputs
AI-Powered Automation
A standout feature of RatHat is its use of generative AI to automate interactions with infected devices. The malware serializes the device’s live Accessibility tree into XML and communicates in Mandarin with an AI assistant likely Google’s Gemini models to perform tasks such as:
- Identifying on-screen coordinates for synthetic clicks
- Extracting text from UI elements (without translation)
- Executing navigation commands (e.g., SCROLL_DOWN)
Impact and Timeline
Zimperium’s zLabs team published their findings on September 16, highlighting RatHat’s novel approach to blending traditional malware techniques with AI-driven automation. The malware’s ability to bypass security controls and leverage AI for operational efficiency marks a concerning evolution in mobile threats.
The discovery underscores the growing sophistication of Android malware, particularly in credential theft and financial fraud campaigns.
Source: https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
Google TPRM report: https://www.rankiteo.com/company/googlecloudsecurity
"id": "goo1789655188",
"linkid": "googlecloudsecurity",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Global', 'type': 'Mobile users'}],
'attack_vector': ['Smishing (SMS phishing)',
'Malvertising',
'Third-party forums'],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Banking credentials',
'2FA/OTP codes',
'Screen activity',
'User inputs']},
'date_detected': '2024-09-16',
'date_publicly_disclosed': '2024-09-16',
'description': 'Security researchers at Zimperium have uncovered RatHat, a '
'sophisticated Android malware strain designed to harvest '
'banking credentials, two-factor authentication (2FA) codes, '
'and one-time passwords (OTPs). RatHat employs advanced '
'techniques for persistence, evasion, and operational control, '
'including the use of generative AI.',
'impact': {'data_compromised': ['Banking credentials',
'2FA/OTP codes',
'Screen activity',
'User inputs'],
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'Android devices'},
'investigation_status': 'Completed',
'lessons_learned': 'The malware’s ability to bypass security controls and '
'leverage AI for operational efficiency marks a concerning '
'evolution in mobile threats.',
'motivation': 'Credential and banking theft, financial fraud',
'post_incident_analysis': {'root_causes': 'Deceptive distribution channels '
'(smishing, malvertising, '
'third-party forums), exploitation '
'of Android’s Accessibility Service '
'controls, and use of generative AI '
'for automation.'},
'references': [{'date_accessed': '2024-09-16', 'source': 'Zimperium zLabs'}],
'response': {'communication_strategy': 'Public disclosure by Zimperium',
'third_party_assistance': 'Zimperium (zLabs)'},
'threat_actor': 'Threat actors operating in China',
'title': 'New Android Malware RatHat Exploits AI for Credential and Banking '
'Theft',
'type': 'Malware',
'vulnerability_exploited': 'Android’s restricted settings and Accessibility '
'Service controls'}