origo.hu · Techbázis ·
RatHat: AI-Powered Malware Takes Over Android Device Control
Zimperium discovered that the RatHat malware, powered by artificial intelligence, spreads through fake Google Play pages and gains full administrative access with user‑approved assistive options. The AI agent records data, bypasses 2FA, and forwards information to attacker servers.
RatHat is a malware designed for Android that operates using artificial intelligence. According to Zimperium, the virus primarily relies on deception and psychological manipulation: it lures users through fake websites to install an application that appears official (e.g., Google Chrome).
Using the granted assistive options, the app enables wireless debugging, then obtains ADB Shell privileges, giving it root‑level access. It subsequently installs an AI agent and a proxy client that collects data and forwards it over a secure channel to attacker servers.
The virus operates invisibly: it logs on‑screen information, records screen taps (decrypting PIN codes and pattern unlocks), and captures 2FA codes received via SMS. Zimperium identified 162 infected apps linked to servers controlled from China, targeting financial apps and banking software.
Traditional antivirus solutions cannot fully remove RatHat because it dynamically changes its behavior and installs hidden system files. The only reliable solution is restoring the device to factory settings.
Defending is easier: avoid suspicious links, install applications solely from the official Google Play Store, do not update or reinstall existing apps from external websites, and deny assistive options – if an app requests them without justification, immediately refuse and delete it.
Source: https://www.origo.hu/techbazis/2026/09/rathat-virus-az-android-legujabb-reme