Technology
New AI-powered malware RatHat targets Android devices and steals sensitive data
CNET reports that security researchers discovered new AI-driven malware that gains admin rights on infected Android devices to steal financial credentials.
The short version
- Security firm Zimperium discovered RatHat, a new AI-assisted malware that tricks Android users into granting accessibility permissions to obtain administrative control.[CNET]
- The malware captures credentials, screen input, and SMS messages, primarily targeting financial services such as WeChat Pay and Alipay.[CNET]
- Researchers have identified 162 infected applications in the wild that communicate with roughly a dozen attacker-operated servers.[CNET]
- Antivirus scans can detect the infection, but removing it completely requires a full factory reset to eliminate hidden persistence files.[CNET]
Key facts
- RatHat tricks users into downloading fake applications from web pages masquerading as the Google Play Store.[CNET]
- The malware uses granted accessibility permissions to enable Wireless Debugging and ADB Shell permissions, acquiring admin control.[CNET]
- RatHat deploys an AI-assisted agent to run system commands and exfiltrate data through a proxy client to remote servers.[CNET]
- Zimperium traced the threat to attackers in China, with primary targets including payment apps like WeChat Pay and Alipay.[CNET]
- At least 162 infected apps have been identified contacting around twelve command-and-control servers.[CNET]
- A complete device factory reset is required for removal because hidden secondary files preserve admin access and repeatedly reinstall the software.[CNET]
What remains uncertain
- The full extent of other financial applications targeted beyond WeChat Pay and Alipay remains unspecified.[CNET]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.