← Latest briefing

Technology

New AI-powered malware RatHat targets Android devices and steals sensitive data

CNET reports that security researchers discovered new AI-driven malware that gains admin rights on infected Android devices to steal financial credentials.

The short version

  • Security firm Zimperium discovered RatHat, a new AI-assisted malware that tricks Android users into granting accessibility permissions to obtain administrative control.[CNET]
  • The malware captures credentials, screen input, and SMS messages, primarily targeting financial services such as WeChat Pay and Alipay.[CNET]
  • Researchers have identified 162 infected applications in the wild that communicate with roughly a dozen attacker-operated servers.[CNET]
  • Antivirus scans can detect the infection, but removing it completely requires a full factory reset to eliminate hidden persistence files.[CNET]

Key facts

  • RatHat tricks users into downloading fake applications from web pages masquerading as the Google Play Store.[CNET]
  • The malware uses granted accessibility permissions to enable Wireless Debugging and ADB Shell permissions, acquiring admin control.[CNET]
  • RatHat deploys an AI-assisted agent to run system commands and exfiltrate data through a proxy client to remote servers.[CNET]
  • Zimperium traced the threat to attackers in China, with primary targets including payment apps like WeChat Pay and Alipay.[CNET]
  • At least 162 infected apps have been identified contacting around twelve command-and-control servers.[CNET]
  • A complete device factory reset is required for removal because hidden secondary files preserve admin access and repeatedly reinstall the software.[CNET]

What remains uncertain

  • The full extent of other financial applications targeted beyond WeChat Pay and Alipay remains unspecified.[CNET]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.