Updated
Updated · zimperium.com · Sep 18
RatHat Malware Steals Android Banking Credentials With AI, Gaining Shell Access via 6-Digit ADB Pairing
Updated
Updated · zimperium.com · Sep 18

RatHat Malware Steals Android Banking Credentials With AI, Gaining Shell Access via 6-Digit ADB Pairing

3 articles · Updated · zimperium.com · Sep 18

Summary

  • Zimperium’s zLabs said RatHat is a newly identified Android malware strain that targets banking and payment users, stealing credentials, OTP codes and lock-screen secrets through fake app screens and input capture.
  • Accessibility abuse and autonomous wireless ADB self-pairing let RatHat escape the normal app sandbox, launch native daemons with shell-level privileges and maintain remote control through a reverse tunnel.
  • Raw touch logging from /dev/input allows the malware to reconstruct PINs, passwords and unlock patterns from finger coordinates, bypassing protections such as FLAG_SECURE, custom keyboards and hidden lock-screen digits.
  • Persistence is built around an out-of-lifecycle background service that survives app removal, silently reinstalls the APK with permissions and restores malicious access if the user uninstalls it.
  • The campaign is spread mainly through smishing, malvertising and deceptive download portals, underscoring a shift toward AI-assisted mobile malware that adapts in real time and resists traditional analysis.

Insights

Why are legitimate Android accessibility features becoming the ultimate backdoor for unremovable banking trojans like RatHat and ToxicPanda?
If removing the malicious app does not stop RatHat, how can users completely eradicate this AI-driven malware from their devices?
How are cybercriminals weaponizing generative AI to read your screen and bypass traditional mobile security defenses in real-time?

Inside RatHat: How AI-Powered Android Malware Redefined Mobile Threats in 2026 and Forced Factory Reset as the Only Cure

Overview

In September 2026, researchers uncovered RatHat, a highly advanced Android malware that uses deceptive smishing and fake apps to trick users into installing it. Once installed, RatHat pressures users to enable Accessibility permissions, then leverages a commercial AI assistant to navigate the device’s interface in real time, making it nearly invisible to traditional security tools. The malware unlocks developer options, pairs with the device’s ADB daemon, and installs hidden native binaries for persistent, privileged control. Even if users try to uninstall it, RatHat can silently reinstall itself. Only a full factory reset can completely remove the infection.

...