AI‑Powered Android Trojan ‘RatHat’ Uses Accessibility Abuse and ADB to Steal Banking Logins and PINs
What Happened — Researchers at Zimperium’s zLabs disclosed a new Android Trojan, RatHat, that combines smishing, accessibility‑service abuse, and an on‑device AI assistant to automate screen taps and scrolls. By enabling Wireless Debugging via ADB, the malware gains a shell‑level session, drops privileged binaries, and harvests banking credentials, OTPs, and PINs.
Why It Matters for Trust & Control Assurance
- Demonstrates how a lack of strict access‑control policies for mobile accessibility services and debugging tools can be weaponised, a scenario continuous‑control‑assurance programs are built to detect and evidence.
- Highlights the need for security‑awareness training around smishing and sideloaded apps, providing audit‑ready evidence of user‑training compliance.
- Shows that AI‑driven, variable attack paths can evade signature‑based detection, underscoring the importance of behavioural monitoring and defensible logs for control‑objective verification.
Who Is Affected – Financial‑services mobile apps, Android device users, and organisations that allow developer‑mode features (e.g., ADB over Wi‑Fi) on employee devices.
Recommended Actions –
- Enforce a policy that disables Android Accessibility Services and Wireless Debugging (ADB) for non‑developer devices.
- Deploy Mobile Device Management (MDM) to monitor and log accessibility‑service activation and ADB connections.
- Conduct targeted security‑awareness training on smishing and sideloading risks.
- Collect and retain logs of accessibility‑service usage as audit evidence for control‑objective compliance.
Source: Malwarebytes Labs
Technical Notes – The infection chain starts with SMS phishing (smishing) that directs victims to a malicious APK. Once installed, the app coerces users into enabling the Accessibility Service, then programmatically turns on Wireless Debugging, reads the pairing code, and establishes a privileged ADB shell. An on‑device AI model decides where to tap, enabling credential overlay attacks and raw‑touch‑coordinate capture to reconstruct PINs. The malware also intercepts SMS and can reinstall itself after removal. Source: same as above