RatHat Android Trojan Uses AI to Steal Bank Logins
Zimperium analyzed RatHat, an Android banking trojan using AI automation and ADB abuse to steal logins, OTPs, and PINs.
Zimperium’s zLabs analyzed RatHat, an Android banking trojan distributed through SMS phishing, or smishing, and malvertising that points victims to fake download pages and sideloaded APKs. A multi-stage infection abuses Accessibility Services to enable wireless debugging, reach the local ADB daemon, leave the app sandbox, and gain shell execution, then drops a Go-based agent and a persistent tunnel; SecurityWeek identifies that tunnel as an FRP-based reverse-proxy client. The malware overlays banking and payment apps, captures the screen and SMS messages including one-time codes, logs input, and reconstructs screen-lock PINs or patterns from raw touch coordinates or hardware touch events. The reports disagree on the AI detail: Cyber Security News says Malwarebytes highlighted a live AI assistant that decides where to tap or scroll, while SecurityWeek says Zimperium describes a generative AI assistant navigating the live accessibility tree and that the prompts suggest a Chinese developer. A hidden component or service can restore or reinstall the app after removal, and Cyber Security News recommends a factory reset.
- Zimperium’s zLabs analyzed RatHat, an Android banking trojan, in reports dated 2026-09-21.
- It is spread by SMS phishing (smishing) and malvertising to fake download pages and sideloaded APKs, using a multi-stage chain that leaves the app sandbox.
- It abuses Accessibility Services to enable wireless debugging, reach the local ADB daemon, and gain shell execution.
- It drops a Go-based agent and a persistent tunnel; SecurityWeek specifies an FRP-based reverse-proxy client.
- It overlays banking and payment apps, captures the screen and SMS or OTP codes, logs input, and reconstructs PINs or unlock patterns from touch data.
- Sources differ on the AI feature: Malwarebytes is cited for a live assistant choosing taps and scrolls, while Zimperium is cited for generative AI navigating the accessibility tree, with prompts suggesting a Chinese developer.
- A hidden component or service can restore or reinstall the app after removal; Cyber Security News says a factory reset is recommended.
Coverage timelineoldest first · each row is one article
- · 5d agoNew Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
Cyber Security News· 65
New Android banking Trojan RatHat uses AI-driven UI automation and ADB wireless debugging abuse to steal bank logins, OTPs, and PINs.
- · 5d agoRatHat Android Trojan Uses AI for Automation
SecurityWeek· 72
Zimperium says RatHat, an Android trojan, uses generative AI to control devices and steal banking credentials.