Skip to content
News

RatHat Malware: AI-Powered Android Threat Steals Data

RatHat Malware: AI-Powered Android Threat Steals Data
RatHat is AI-powered Android malware that gains admin control to steal passwords, 2FA codes and financial data. Learn how it works and how to remove it.

RatHat is a newly discovered AI-powered malware that can automatically gain admin-level control over an Android device and steal a wide range of sensitive information. The threat was identified by mobile security firm Zimperium, and researchers say it poses a significant risk to unsuspecting users across the Android ecosystem.

The malware spreads by tricking people into downloading what appears to be a legitimate application, such as Google Chrome, through a fake web page designed to mimic the Google Play Store. Once opened, the app requests accessibility permissions, which it then abuses to take over the entire device.

How RatHat takes control

Using the accessibility permissions granted by the user, RatHat navigates the phone’s menu system and unlocks Wireless Debugging, a legitimate developer tool commonly used in app testing. It then grants itself ADB Shell permissions, effectively giving the malware administrator-level access. From there, it installs an AI-assisted agent that runs system commands to harvest information, alongside a proxy client that tunnels the stolen data back to the attacker.

Security researchers have noted that this infection chain is not necessarily more complex than following a phishing email on Windows and approving administrator permissions. Escalation on Android often relies on persuading users to grant apps additional permissions that the operating system locks away by default to keep devices secure.

The malware has been traced to attackers in China and primarily targets apps such as WeChat Pay and Alipay, though other financial apps can also be affected. To date, researchers have found 162 infected apps in circulation, reporting back to roughly a dozen servers operated by the attackers.

What the malware can steal

One of the most troubling aspects of RatHat is that it does nothing immediately noticeable, unlike a ransomware attack. Instead, it runs quietly in the background and captures information displayed on the screen, including usernames, passwords and two-factor authentication codes.

It can also steal raw touch input from the touchscreen, allowing it to recreate PIN codes and pattern unlock codes. In addition, it can capture SMS messages, intercepting security codes as they arrive. There is little the malware cannot access once it is established on a device.

The only reliable way to detect RatHat is to run an antivirus scan capable of identifying it. A free option available on Google Play can detect the malware fairly easily, offering reassurance to anyone concerned about a possible infection.

Removing it, however, is far more difficult. Because the program remasquerades as other apps and dynamically changes its behaviour through an AI endpoint, static analysis and quarantining alone are not enough to eliminate it. The only way to fully remove RatHat is a complete factory reset of the device, which clears the hidden secondary files the malware installs that antivirus apps cannot address.

Source
Image: cnet.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals