Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

AI‑Powered RatHat Android Malware Automates Device Control and Harvests Credentials

Zimperium researchers uncovered RatHat, an Android malware family that employs a large‑language‑model‑driven UI engine to navigate compromised phones, abuse Accessibility and ADB privileges, and exfiltrate banking and crypto credentials. The AI‑enabled automation makes detection harder and stresses the need for continuous control‑assurance of privileged mobile permissions.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

AI‑Powered RatHat Android Malware Automates Device Control and Harvests Credentials

What Happened — Researchers at Zimperium zLabs identified a new Android malware family, RatHat, that leverages a large‑language‑model‑driven UI‑automation engine to navigate compromised phones. The malware abuses Accessibility permissions, enables Developer Options and Wireless Debugging, and uses ADB‑level agents to maintain persistence and exfiltrate banking, cryptocurrency and OTP data.

Why It Matters for Trust & Control Assurance

  • Demonstrates how privileged Android controls (Accessibility, Developer Options, ADB) can be subverted, underscoring the need for continuous monitoring of high‑risk permissions.
  • AI‑driven automation makes malicious behavior harder to detect with static signatures, highlighting the importance of evidence‑based control assurance that captures behavioral anomalies.
  • Provides a concrete scenario where a control‑assurance program must prove that privileged access is limited, logged, and regularly reviewed.

Who Is Affected — Mobile‑first financial services, cryptocurrency wallets, telecom carriers, and any organization that distributes or relies on Android apps for customer interaction.

Recommended Actions

  • Enforce strict app vetting and block installations from unknown sources.
  • Restrict Accessibility and Developer Options to a whitelist of approved apps; monitor ADB activation events.
  • Deploy behavioral analytics that flag AI‑generated UI interactions or anomalous accessibility usage.
  • Incorporate AI‑tool usage policies into your mobile security governance framework.

Source: BleepingComputer

Technical Notes — RatHat is delivered via malvertising, SMS phishing, and rogue APK sites. It serializes the Android Accessibility tree to XML, sends it to an external AI assistant for navigation commands, and uses two native agents (liblocal-service.so, libmedia_codec.so) for persistence and reverse‑proxy tunneling. The malware captures UI overlays for banking/crypto apps, intercepts SMS OTPs, and can restore itself after removal attempts. Source: same

📰 Original Source
https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →