New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
New Android banking Trojan RatHat uses AI-driven UI automation and ADB wireless debugging abuse to steal bank logins, OTPs, and PINs.
Zimperium's zLabs analyzed RatHat, an Android banking Trojan distributed via SMS phishing and malicious ads pointing to fake app download pages. It abuses Accessibility Services to enable Wireless Debugging, pairs via ADB, and drops a Go-based agent plus a persistent tunnel to attacker infrastructure. It overlays fake screens on banking apps, intercepts SMS codes, and reconstructs screen-lock PINs or patterns from raw touch coordinates recorded via the input driver. Malwarebytes highlighted its use of a live AI assistant to decide where to tap or scroll, weakening signature-based detection.
- Distributed via SMS phishing and malvertising leading to sideloaded APKs.
- Uses Accessibility Service abuse to enable Wireless Debugging and self-pair over ADB.
- Drops a Go-based agent and persistent tunnel surviving network barriers.
- Records raw touch coordinates to reconstruct PINs and unlock patterns.
- Hidden component restores the app after removal; factory reset recommended.
Full article679 words · extracted from cybersecuritynews.com · click to collapse
A newly identified Android banking Trojan called RatHat uses phone features for account theft. The malware can guide itself through an infected device, capture banking logins, intercept verification codes and reconstruct a victim’s screen-lock PIN or pattern.
The campaign begins with deception rather than a software flaw. Victims receive SMS phishing messages or see malicious adverts leading to fake download pages, often posing as a familiar app.
The pages persuade people to install an Android app package from outside an official store. Malwarebytes noted the threat after Zimperium’s zLabs analysed its multi-stage operation.
Malwarebytes said in a report shared with Cyber Security News (CSN) that RatHat combines social engineering, accessibility abuse and remote AI-driven decisions.
Instead of using only fixed instructions, RatHat can use a live AI assistant to inspect the interface and decide where to tap or scroll. This variability may weaken simple signature-based detection and give criminals more routes to financial apps.
New Android Malware Uses AI
After installation, RatHat pressures the victim to enable Android’s Accessibility Service, claiming a network restriction must be removed or offering a false financial benefit.
Once approved, the permission lets the app view screen content and act for the user, creating a path like the Android banking Trojan activity reported in other campaigns.
RatHat uses those controls to enable Wireless Debugging and read the six-digit pairing code. It pairs itself through Android Debug Bridge, or ADB, a legitimate developer tool. This misuse of wireless debugging abuse techniques gives the malware a shell-level session beyond an ordinary app’s limits.
With that access, the Trojan drops two concealed native components. A Go-based agent runs system commands, while another component establishes a continuing tunnel to an attacker-controlled server. The tunnel can retain access through network barriers and support remote activity.
For banking theft, RatHat places fake screens over targeted financial apps to collect usernames, passwords and one-time passwords. It can also intercept SMS messages, weakening protections that depend on texted codes.
The broader one-time code theft risks show why a stolen password alone is no longer the only concern. Its most unusual feature records raw coordinates from the phone’s input driver, capturing where a finger touches the display.
RatHat compares those points with keypad and pattern-lock layouts to rebuild PINs or unlock patterns. Because it uses touch locations rather than only reading the screen, the method can bypass protections meant to stop screen capture.
Persistence raises the recovery stakes
RatHat can restore its malicious app after a user removes it by relying on a hidden background component. Deleting a suspicious app may therefore not end the compromise.
The design also reflects Android threats that blend fake apps, deep permissions and remote control, including hidden work profile schemes used to evade fraud checks.
The strongest protection remains avoiding the first permission grant. Users should install apps only from Google Play or another trusted official store, treat unsolicited links and adverts with caution, and reject Accessibility requests that do not clearly support a genuine accessibility function.
An entertainment, finance or browser app has no normal reason to demand that level of control. Users should leave Developer Options and Wireless Debugging disabled unless they understand and need them for development.
Keeping Android and mobile security software current can improve detection, but it is not a substitute for careful installation choices. Advanced Protection Mode may further limit which apps can request accessibility access on supported devices.
Anyone who believes RatHat reached their phone should act quickly. Change banking passwords from a separate trusted device, contact the bank to review access and transactions, and seek professional support.
Since its persistence can survive routine app removal, researchers recommend a factory reset before restoring only essential, trusted data.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.