New RatHat Android Malware Uses AI to Steal Banking Logins, PINs and OTP Codes

September 19, 2026

Security researchers have recently unveiled a sophisticated Android banking Trojan known as RatHat. This malware stands out for its innovative blend of artificial intelligence (AI), exploitation of accessibility features, and the capabilities of Android Debug Bridge (ADB) to pilfer financial credentials, PINs, and one-time passcodes.

RatHat Android Malware

According to findings from MalwareBytes, RatHat diverges from conventional Android malware by not relying solely on pre-programmed automation scripts. Instead, it features a live AI assistant that interacts with the Android accessibility tree. This allows RatHat to interpret the content displayed on a victim’s screen and make real-time decisions about where to tap, scroll, or input data.

This AI-driven approach complicates detection efforts. Traditional mobile security solutions typically identify malicious activities based on fixed behavior patterns, such as overlay templates or hardcoded automation sequences. RatHat, however, adapts its navigation paths based on various factors, including device settings, installed applications, and the specific screens presented to the user.

The infection process often begins with social-engineering tactics, such as smishing messages and deceptive advertisements. Victims are lured to counterfeit download pages masquerading as trusted applications, including popular streaming platforms or web browsers. These pages prompt users to sideload a malicious Android Package Kit (APK) outside of official app stores.

Upon installation, the malware attempts to convince victims to enable Android Accessibility Service permissions through misleading prompts, which may include fake network-restriction messages or claims of financial incentives. These permissions are particularly coveted by attackers, as they allow the app to read screen content, monitor user actions, and interact with other applications.

Once it has acquired these permissions, RatHat exploits them to navigate through Android’s Developer Options and enable Wireless Debugging. The Trojan reads the six-digit wireless pairing code displayed on the device, establishing an ADB connection without needing a legitimate developer workstation.

With shell-level ADB access, RatHat can circumvent standard application sandbox restrictions. Researchers have confirmed that it deploys two native binaries: a Go-based agent that executes system commands and a reverse-proxy component that maintains a persistent connection to infrastructure controlled by the attacker.

This connection allows remote operators to access the compromised device while bypassing common network barriers, such as NAT and firewall controls. RatHat specifically targets banking and financial applications through credential-stealing overlays, creating fake interfaces that mimic legitimate apps to capture usernames, passwords, payment information, and multi-factor authentication codes. Additionally, it can intercept SMS messages, granting attackers access to transaction verification codes and other one-time passcodes (OTPs).

One particularly alarming feature of this Trojan is its ability to record raw touch coordinates from the device’s input driver. By comparing these coordinates with known keypad and pattern-lock layouts, RatHat can reconstruct PINs and unlock patterns, potentially bypassing protections that prevent accessibility services from accessing sensitive screen content directly.

Moreover, RatHat incorporates persistence mechanisms designed to restore the malicious application even after it has been removed. Users who suspect their devices have been compromised should consider performing a factory reset rather than simply uninstalling the app.

To mitigate the risk of infection, Android users are advised to refrain from sideloading apps from unsolicited links, deny unnecessary Accessibility Service requests, and avoid enabling Developer Options or Wireless Debugging for unknown applications.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team.

AppWizard
New RatHat Android Malware Uses AI to Steal Banking Logins, PINs and OTP Codes