Cybersecurity researchers at Zimperium have identified a new and sophisticated strain of malware known as RatHat, specifically targeting Android devices. This malware has been linked to threat actors operating from China and employs innovative techniques to maintain persistence while utilizing generative AI for operational control.
How RatHat Operates
According to a report from Zimperium’s zLabs, RatHat functions by providing a live AI assistant with access to the accessibility tree of the infected device. This unique application of AI enables attackers to determine where to tap or scroll, rather than relying on a rigidly defined script.
The initial infection typically occurs through social engineering tactics. Attackers lure victims into downloading what appears to be a legitimate application, such as Google Chrome, from a counterfeit website masquerading as the Google Play Store. Unbeknownst to the user, this seemingly innocuous app is actually harboring the RatHat malware.
Once installed, RatHat requests accessibility permissions while still posing as a legitimate application. Upon receiving these permissions, it activates Wireless Debugging under Developer Options, effectively weaponizing a genuine Android developer feature to establish a connection with the device. This access allows RatHat to capture text messages, create overlays on targeted applications, and steal passwords along with multi-factor authentication codes.
Zimperium explains that RatHat’s AI capabilities enable it to navigate and control the device interface in real-time, making its operations more adaptable and significantly harder for security software to detect compared to traditional scripted automation. Additionally, the overlay functions similarly to a keylogger, recording the user’s raw touch inputs directly on the device.
To safeguard against RatHat, Android users are advised to refrain from downloading applications from untrustworthy sources. Unfortunately, once a device is compromised by RatHat, the only viable solution for removal is to perform a factory reset.