New RatHat Android Malware Deploys AI to Automate Device Control and Steal Banking Credentials
Zimperium discovered RatHat, an AI-powered Android malware linked to China-based threat actors that abuses accessibility permissions to gain shell-level control. The banking trojan uses generative AI to navigate device interfaces, record screen touches, and steal credentials from apps like WeChat Pay and Alipay. With 162 infected apps found, the malware persists even after uninstall attempts, requiring a factory reset for complete removal.