logo

New RatHat Android Malware Uses AI to Automate Device Control

ID: 1566dba0-247f-5a8b-b262-21d43c15fb4a

STIX ID: report--1566dba0-247f-5a8b-b262-21d43c15fb4a

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-09-17

Date Updated: 2026-09-18

...
...

Zimperium zLabs discovered RatHat, an Android remote-access trojan that uses an AI subsystem to parse the accessibility tree and generate navigation commands—making it resilient to UI changes—and is distributed via malvertising, SMS, and phishing-driven APK sideloads. RatHat abuses Accessibility permissions to perform device takeover actions (enable Developer Options, install ADB-privileged agents, display credential-harvesting overlays, intercept SMS/OTPs, record keystrokes, capture PINs), includes native libraries and obfuscation techniques, and uses FRP for persistent reverse-proxy C2; the report includes technical indicators and mitigation advice (avoid sideloading, scrutinize Accessibility requests, prefer non-SMS 2FA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.