RatHat Android Malware Uses AI to Mimic Human Interaction

A newly identified Android malware strain, RatHat, is leveraging generative AI to navigate infected devices in real-time. By gaining control over accessibility features, the software bypasses traditional scripted automation, allowing attackers to perform dynamic swipes and taps to harvest sensitive data like passwords and multi-factor authentication codes.

Today, 02:16
515 0
RatHat Android Malware Uses AI to Mimic Human Interaction

Discovered by researchers at Zimperium, the malware is linked to threat actors operating from China. The infection process begins through social engineering, where users are tricked into downloading fake applications from websites masquerading as the official Google Play Store. Once installed, the malware requests accessibility permissions and enables Wireless Debugging, granting it deep-level control over the device interface.

Unlike traditional automation tools, RatHat utilizes an AI assistant to analyze the device's accessibility tree, enabling it to intelligently interact with banking apps or messaging services. Beyond its navigation capabilities, the malware functions as a sophisticated keylogger by recording raw touch inputs through screen overlays. Security experts warn that the software's adaptability makes it exceptionally difficult for standard security tools to detect. If a device is compromised, the only effective remedy is a complete factory reset.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!