AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
ID: ebb652c8-6eac-5215-b1c4-130e1eed2514
STIX ID: report--ebb652c8-6eac-5215-b1c4-130e1eed2514
Feed Name: GBHackers
**Executive Summary:** RatHat is an AI-powered Android banking trojan analyzed by zLabs that automates device compromise by abusing Accessibility services, enabling Wireless Debugging/ADB pairing, installing native agents (including a Go-based command agent and reverse proxy), and using credential-harvesting overlays, SMS interception, and raw touch-coordinate collection to steal banking credentials, OTPs, PINs and unlock patterns; distribution is via smishing and malicious download pages, and remediation may require a factory reset.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
