Updated
Updated · CNET · Sep 20
RatHat Malware Hijacks Android Phones via 162 Fake Apps as AI Agent Steals Passwords
Updated
Updated · CNET · Sep 20

RatHat Malware Hijacks Android Phones via 162 Fake Apps as AI Agent Steals Passwords

3 articles · Updated · CNET · Sep 20

Summary

  • Zimperium found RatHat in 162 infected Android apps that impersonate legitimate downloads, then use granted accessibility permissions to seize admin-level control through Wireless Debugging and ADB Shell access.
  • That access lets an AI-assisted agent quietly capture on-screen data, touch input, SMS messages, passwords and two-factor codes, while a proxy tunnels the stolen information to about 12 attacker-run servers.
  • China-linked operators appear to be targeting WeChat Pay and Alipay most heavily, though researchers said other financial apps can also be compromised.
  • Malwarebytes said antivirus scans can detect RatHat, but removal requires a full factory reset because hidden files preserve its privileges and can reinstall the app after deletion.
  • The main defenses are avoiding links from unsolicited texts or emails, verifying downloads come from the real Google Play app rather than a lookalike website, and refusing accessibility permissions.

Insights

How does RatHat's generative AI process your phone's accessibility data in real-time to hijack banking apps without triggering alarms?
If traditional antivirus fails against RatHat's advanced evasion tactics, what hidden signs reveal that your device is already compromised?