New RatHat Android malware uses AI to automate device control

A New Breed of Android Malware Leverages AI to Automate Device Control

Cybersecurity researchers have uncovered a sophisticated Android malware strain called RatHat, which uses artificial intelligence (AI) to navigate and control compromised devices with unprecedented ease. This highly adaptable malware is being distributed through malicious advertisements, phishing websites, and SMS scams, targeting users who download APK files from outside the Google Play Store.

RatHat’s arsenal of capabilities includes displaying fake HTML overlays on targeted banking and cryptocurrency apps to steal account credentials, intercepting SMS messages and notifications for one-time passwords, recording text-change events, extracting URLs from browser address bars, and capturing lock-screen PINs, passwords, and unlock patterns. The malware also employs a persistence mechanism, restoring itself even if the user attempts to remove it.

What sets RatHat apart is its AI-powered subsystem, which enables remote navigation of the device interface without requiring real-time interaction from the operators. This engine serializes the live Android Accessibility tree into XML and sends it to an unspecified popular AI assistant, allowing the malware to intelligently identify elements on-screen, determine their actual text, and provide navigation instructions such as scrolling or tapping.

This AI-guided approach makes RatHat’s automation more adaptable than traditional scripted methods, making it harder for security software to detect. Zimperium researchers warn that RatHat will actively thwart removal attempts by intercepting the uninstall confirmation screen and displaying fake error messages.

RatHat’s tactics are not unique in the Android malware landscape. Similar strains like ToxicPanda and RedHook have employed similar mechanisms to gain local shell-level execution contexts without requiring external computers. However, RatHat’s use of AI-powered automation raises the bar for malicious actors, enabling them to evade detection and persistence channels that are independent of the malware itself.

As users become increasingly reliant on their mobile devices for financial transactions and personal data storage, it is essential to exercise caution when interacting with APK files outside of Google Play. Android users should avoid granting Accessibility permissions to apps, regularly scan their devices with Play Protect, and refrain from downloading files from untrusted sources.

The emergence of RatHat highlights the evolving threat landscape in mobile cybersecurity, where AI-powered attacks are becoming increasingly common. As defenders struggle to keep pace with these sophisticated threats, it is crucial for users to stay informed about the latest security risks and adopt best practices to protect their devices and sensitive information.


Source: Bleeping Computer — 2026-09-17