Techradar AI-Powered Android Malware RedHat Survives Deletion and Steals Banking Credentials
Article Content
- •RedHat malware uses AI to adapt to banking app changes and steal credentials.
- •The malware can reinstall itself and block uninstallation attempts.
- •Cisco's CVE-2026-76460 is actively exploited, posing a critical risk to users.
A new Android banking trojan named RedHat has been discovered, featuring an AI component that allows it to adapt to changes in banking app layouts. This malware can create invisible overlays to capture user credentials and one-time passwords, effectively controlling victims' banking accounts. It is distributed through third-party app stores, social media, and malvertising, requiring Accessibility permissions to operate. Notably, RedHat can reinstall itself after deletion and block uninstall attempts by displaying fake error messages. Cisco has also reported a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine, which has been actively exploited, allowing unauthorized access to affected systems. Organizations using Cisco ISE are urged to patch their systems immediately to mitigate risks. The situation highlights the growing intersection of AI and malware, raising concerns for cybersecurity professionals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track RatHat, Cisco and CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
RatHat Android Malware Exploits Accessibility for Deep Device Control RatHat is a newly discovered Android trojan linked to China-based threat actors, utilizing AI to gain extensive control over infected devices. It is primarily distributed through deceptive phishing campaigns, malvertising, and third-party app stores, tricking users into downloading malicious APKs. Once installed…
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents Plugin4Shell is a critical zero-click remote code execution vulnerability affecting four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. Discovered by AIR Security, this flaw allows attackers to exploit trusted plugin marketplaces by swapping legitimate plugins with malicious ones, gaining…