← AI news

hvg.hu · Tech ·

RatHat Android Malware Uses Chinese Language Model, Even Deploying AI

Zimperium zLabs researchers discovered that the RatHat Android malware employs artificial intelligence for targeted attacks. The program uses a Chinese LLM for commands and can bypass two‑factor authentication.

Zimperium zLabs security researchers identified a new Android malware called RatHat, which applies artificial intelligence during targeted attacks. The malware uses a Chinese language model (LLM) for commands and spreads through trap ads, SMS messages, and phishing sites.

RatHat can exploit the device’s assistive features to gain access to the system and execute commands. The malware installs an agent that bypasses restrictions, reinstalls itself after every removal attempt, and ensures persistent presence.

Attackers display a fake HTML page in banking and cryptocurrency apps to capture users’ login credentials. They also read SMS messages and unique one‑time passwords, thereby circumventing two‑factor authentication. In the browser, they obtain links, passwords, and codes required for mobile unlocking.

The AI automates malicious activity, so the attacker does not need to manually handle details. The AI can issue instructions, navigate, and control actions on the device, making it difficult for security software to mitigate the malware.

Source: https://hvg.hu/tudomany/20260918_android-hackertamadas-mesterseges-intelligencia-adatok-ellopasa