Skip to content
AI-Powered Android Malware RedHat Survives Deletion and Steals Banking Credentials

AI-Powered Android Malware RedHat Survives Deletion and Steals Banking Credentials

First seen 18 Sep 2026, 20:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 21:53 UTC
  • RedHat malware uses AI to adapt to banking app changes and steal credentials.
  • The malware can reinstall itself and block uninstallation attempts.
  • Cisco's CVE-2026-76460 is actively exploited, posing a critical risk to users.

A new Android banking trojan named RedHat has been discovered, featuring an AI component that allows it to adapt to changes in banking app layouts. This malware can create invisible overlays to capture user credentials and one-time passwords, effectively controlling victims' banking accounts. It is distributed through third-party app stores, social media, and malvertising, requiring Accessibility permissions to operate. Notably, RedHat can reinstall itself after deletion and block uninstall attempts by displaying fake error messages. Cisco has also reported a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine, which has been actively exploited, allowing unauthorized access to affected systems. Organizations using Cisco ISE are urged to patch their systems immediately to mitigate risks. The situation highlights the growing intersection of AI and malware, raising concerns for cybersecurity professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-76460 published
Cisco disclosed a maximum-severity vulnerability in its Identity Services Engine, allowing unauthorized access.
Hindustantimes
2026-09-16
CVE-2026-76460 added to CISA KEV
CISA included the vulnerability in its Known Exploited Vulnerabilities catalog due to active exploitation.
Hindustantimes
2026-09-17
First public PoC for CVE-2026-76460
Proof-of-concept code for the Cisco vulnerability was made publicly available, increasing the urgency for patching.
Hindustantimes
Recent
Discovery of RedHat malware
Zimperium zLabs identified RedHat, an AI-powered Android banking trojan that can adapt to app changes and steal credentials.
Techradar

More articles in this cluster (2)

Following this threat?

Track RatHat, Cisco and CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed