Skip to content
RatHat Android Malware Uses AI for Persistent Control and Data Theft

RatHat Android Malware Uses AI for Persistent Control and Data Theft

First seen 18 Sep 2026, 12:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 15:58 UTC
  • RatHat malware uses AI for automated device control and evasion of detection.
  • It exploits Accessibility permissions to gain shell-level access on Android devices.
  • The malware employs multiple anti-analysis techniques to complicate detection efforts.

Cybersecurity researchers have identified a new Android malware named RatHat, believed to be operated by China-based threat actors. This malware exploits Android's Accessibility permissions and uses an AI-powered subsystem to automate device control, making it harder to detect. RatHat is distributed through targeted smishing and malvertising campaigns, leading users to install malicious APKs from deceptive sources. Once installed, it can enable Developer Options and Wireless Debugging to gain shell-level access without external devices. The malware features multiple anti-analysis techniques to evade detection and can intercept SMS messages, capture credentials, and display fake overlays for banking apps. It is designed to maintain persistence even after attempts to uninstall it. Zimperium researchers have linked the malware to Chinese threat actors based on the use of Chinese language prompts in its code.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
RatHat malware discovered
Zimperium researchers identified RatHat, linking it to Chinese threat actors and detailing its capabilities.
BleepingComputer
2026-09-18
RatHat malware reported by The Hacker News
The Hacker News published a detailed analysis of RatHat, emphasizing its multi-stage infection pipeline and anti-analysis techniques.
The Hacker News

More articles in this cluster (2)

Following this threat?

Track ToxicPanda and RatHat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed