RatHat Malware Hijacks Android Phones via 162 Fake Apps as AI Agent Steals Passwords
Updated
Updated · CNET · Sep 20
RatHat Malware Hijacks Android Phones via 162 Fake Apps as AI Agent Steals Passwords
3 articles · Updated · CNET · Sep 20
Summary
Zimperium found RatHat in 162 infected Android apps that impersonate legitimate downloads, then use granted accessibility permissions to seize admin-level control through Wireless Debugging and ADB Shell access.
That access lets an AI-assisted agent quietly capture on-screen data, touch input, SMS messages, passwords and two-factor codes, while a proxy tunnels the stolen information to about 12 attacker-run servers.
China-linked operators appear to be targeting WeChat Pay and Alipay most heavily, though researchers said other financial apps can also be compromised.
Malwarebytes said antivirus scans can detect RatHat, but removal requires a full factory reset because hidden files preserve its privileges and can reinstall the app after deletion.
The main defenses are avoiding links from unsolicited texts or emails, verifying downloads come from the real Google Play app rather than a lookalike website, and refusing accessibility permissions.