Security researchers have found an Android malware strain called RatHat that uses AI to help steal banking logins, intercept authentication codes, and reconstruct PINs from a user's screen taps.

Follow America's fastest-growing news aggregator, Spreely News, and stay informed. You can find all of our articles plus information from your favorite Conservative voices. 

Security researchers have identified a new strain of Android malware, dubbed RatHat, that uses generative AI to help steal banking credentials, intercept authentication codes, and even reconstruct a phone’s PIN or unlock pattern by tracking where a user’s finger touches the screen.

The discovery comes from researchers at Zimperium, who found that RatHat can convert permissions users unknowingly approve into deep control over an infected device, including the ability to persist on a phone even after the malicious app is deleted.

How the infection spreads

RatHat relies on tricking people into installing it rather than exploiting a hidden flaw. Zimperium says the malware spreads primarily through SMS phishing, malicious advertising, and deceptive third-party download sites, often disguised as familiar software such as a streaming app or Chrome. Victims are led to manually install an APK file outside the official Google Play Store.

Once installed, the app pressures users to enable Android’s Accessibility service, sometimes falsely claiming the permission will fix a network issue or unlock a financial benefit. That service, meant for legitimate accessibility functions, also lets an approved app inspect the screen and interact with the interface on a user’s behalf.

From one permission to full control

With Accessibility access granted, RatHat can tap through phone settings on its own to enable Developer Options and Wireless Debugging, then read the six-digit pairing code for Android Debug Bridge (ADB) and connect to the device’s own debugging interface without need of a separate computer. That gives the malware shell-level access outside Android’s normal app sandbox, letting it run a Go-based agent capable of executing system commands and maintaining a persistent connection back to the attacker.

RatHat also feeds data from Android’s live Accessibility tree to a generative AI assistant, which helps it read on-screen text, locate items, and decide when to scroll — making the malware more adaptable than earlier automated threats that followed a fixed script.

What it can steal

Once embedded, RatHat watches for financial apps and can display fake overlay screens on top of legitimate ones, tricking users into typing banking credentials directly into attacker-controlled pages. Zimperium found it targeting banking and cryptocurrency apps, as well as payment services including WeChat and Alipay. The malware can also intercept SMS messages and notifications to capture one-time passwords and two-factor codes.

Perhaps most alarming, RatHat monitors raw touch coordinates and compares them against known keypad layouts to reconstruct PINs and unlock patterns — a technique that works at a low enough level to bypass protections meant to hide PIN digits from screen readers.

The malware is also built to resist removal. Zimperium found it can block a user’s attempt to uninstall it, placing a fake Google Play error message over the screen, and can run a separate background service that survives deletion of the visible app, allowing it to reinstall itself. It can also request Device Admin rights, which could be used to wipe a device if someone tries to remove it.

Google’s response

Google told CyberGuy it has not found RatHat on the Play Store.

Add comment

Your email address will not be published. Required fields are marked *