logo

AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes

ID: ebb652c8-6eac-5215-b1c4-130e1eed2514

STIX ID: report--ebb652c8-6eac-5215-b1c4-130e1eed2514

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Divya

...
...

**Executive Summary:** RatHat is an AI-powered Android banking trojan analyzed by zLabs that automates device compromise by abusing Accessibility services, enabling Wireless Debugging/ADB pairing, installing native agents (including a Go-based command agent and reverse proxy), and using credential-harvesting overlays, SMS interception, and raw touch-coordinate collection to steal banking credentials, OTPs, PINs and unlock patterns; distribution is via smishing and malicious download pages, and remediation may require a factory reset.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.