by

RatHat malware lets AI drive Android phone

A nasty new Android trojan called RatHat is using AI to navigate infected phones while stealing banking details and locking itself in.

Security researchers at Zimperium zLabs discovered the malware, which they believe is linked to threat actors operating from China after finding large-language-model prompts written in Chinese.

According to BleepingComputer, RatHat is being spread through malvertising, SMS phishing and dodgy websites encouraging victims to install APK files from outside Google Play.

Once aboard, it abuses Android Accessibility permissions to gain extensive control of the device. RatHat then enables Developer Options and Wireless Debugging, giving itself local shell-level execution without needing an external computer.

The malware installs a Go-based agent disguised as liblocal-service.so. Running with ADB shell privileges, the agent executes commands, bypasses battery restrictions, and helps keep the infection alive.

If the Android application is removed, the independent Go service can reinstall it. If the service is killed, the Android application can redeploy it.

RatHat deploys a second component, libmedia_codec.so, which is really an FRP reverse-proxy client. This establishes a persistent tunnel from the compromised device to the attacker. RatHat can place fake HTML interfaces over legitimate financial apps to harvest account credentials and payment PINs. It can intercept SMS messages and notifications, including one-time passwords, record text changes and grab URLs from browser address bars. Lock-screen PINs, passwords and unlock patterns are fair game too.

The more unusual trick is an AI-powered interface automation engine. RatHat serialises Android’s live Accessibility tree into XML, then feeds it to what Zimperium described as one of the world’s most popular generative AI assistants.

The AI can identify the centre coordinates of interface elements, determine the text displayed on screen and return navigation commands such as SCROLL_DOWN. That lets the malware adapt to whatever interface it encounters instead of relying entirely on hard-coded scripts.

“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation,” Zimperium said.

RatHat also puts effort into annoying security researchers. Its defences include APK container tampering, invalid DEX pseudo-instructions and an Android manifest swollen to 61MB, with 99 per cent of it made from undocumented chunks intended to confuse analysis tools.

Trying to uninstall the thing may not get very far. RatHat can intercept Android’s uninstall confirmation screen, cancel the process and throw up a fake Google Play error message. Zimperium said users should avoid APKs from untrusted sources, be suspicious of applications requesting Accessibility permissions and regularly check devices with Google Play Protect.

 

 

TOPICS:
Android  ·  android malware  ·  artificial intelligence  ·  banking trojan  ·  cybersecurity  ·  malware  ·  mobile security  ·  RatHat  ·  Zimperium

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews