New RatHat Android malware uses AI to automate device control
RatHat is a newly discovered Android malware that leverages AI to automate remote control of infected devices. It abuses Android Accessibility permissions to perform privileged actions, including enabling Developer Options and Wireless Debugging to gain shell-level access without external devices. RatHat installs a persistent Go-based agent that manages execution, persistence, and restoration of the malware and its components. It captures sensitive information such as banking credentials, SMS messages, one-time passwords, and lock-screen PINs via overlays and keylogging. The AI subsystem enables adaptive interface navigation by analyzing the live Accessibility tree and issuing dynamic commands, making detection and removal more difficult. The malware also employs anti-analysis and anti-removal techniques, including fake uninstall screens and obfuscation methods. Distribution occurs through malvertising, SMS, and phishing sites promoting APKs outside Google Play.
AI Analysis
Technical Summary
RatHat Android malware uses an AI-powered user interface automation engine that serializes the live Accessibility tree and sends it to an AI assistant to identify UI elements and generate navigation commands. This allows operators to remotely control infected devices without real-time interaction. The malware abuses Accessibility permissions to enable Developer Options and Wireless Debugging, gaining ADB shell-level access to install a Go-based agent (liblocal-service.so) that runs commands, bypasses battery restrictions, and maintains persistence by restoring itself and the agent if removed. A second agent (libmedia_codec.so) establishes a persistent reverse-proxy tunnel to the attacker. RatHat captures credentials via HTML overlays targeting banking and cryptocurrency apps, intercepts SMS and notifications including OTPs, records text changes, extracts URLs, and captures lock-screen PINs and patterns. It thwarts removal by intercepting uninstall confirmation and displaying fake Google Play overlays. Anti-analysis techniques include APK container tampering, a large manifest file, and invalid DEX instructions. Distribution vectors include malvertising, SMS, and phishing sites offering APK downloads outside Google Play. Researchers link the malware to Chinese threat actors based on AI prompt language.
Potential Impact
RatHat enables attackers to gain persistent, high-privilege control over infected Android devices without requiring physical access or external debugging hardware. It can steal sensitive user credentials, including banking and cryptocurrency account information, intercept SMS messages and one-time passwords, and capture lock-screen authentication data. The malware's AI-driven interface automation makes detection and removal more difficult, increasing the risk of prolonged compromise. Its persistence mechanisms ensure it can restore itself and maintain access even after partial removal attempts. The malware's ability to establish a reverse-proxy tunnel further facilitates covert command and control communications.
Mitigation Recommendations
No official patch or fix is available as this is malware rather than a software vulnerability. Users should avoid downloading APK files from outside Google Play unless the publisher is explicitly trusted. Accessibility permissions should not be granted to untrusted apps. Regular scanning with Google Play Protect or equivalent mobile security solutions is recommended. Users should be cautious of malvertising, SMS, and phishing sites promoting APK downloads. Due to the malware's anti-removal techniques, manual removal may be difficult and professional assistance may be required.
New RatHat Android malware uses AI to automate device control
Description
RatHat is a newly discovered Android malware that leverages AI to automate remote control of infected devices. It abuses Android Accessibility permissions to perform privileged actions, including enabling Developer Options and Wireless Debugging to gain shell-level access without external devices. RatHat installs a persistent Go-based agent that manages execution, persistence, and restoration of the malware and its components. It captures sensitive information such as banking credentials, SMS messages, one-time passwords, and lock-screen PINs via overlays and keylogging. The AI subsystem enables adaptive interface navigation by analyzing the live Accessibility tree and issuing dynamic commands, making detection and removal more difficult. The malware also employs anti-analysis and anti-removal techniques, including fake uninstall screens and obfuscation methods. Distribution occurs through malvertising, SMS, and phishing sites promoting APKs outside Google Play.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RatHat Android malware uses an AI-powered user interface automation engine that serializes the live Accessibility tree and sends it to an AI assistant to identify UI elements and generate navigation commands. This allows operators to remotely control infected devices without real-time interaction. The malware abuses Accessibility permissions to enable Developer Options and Wireless Debugging, gaining ADB shell-level access to install a Go-based agent (liblocal-service.so) that runs commands, bypasses battery restrictions, and maintains persistence by restoring itself and the agent if removed. A second agent (libmedia_codec.so) establishes a persistent reverse-proxy tunnel to the attacker. RatHat captures credentials via HTML overlays targeting banking and cryptocurrency apps, intercepts SMS and notifications including OTPs, records text changes, extracts URLs, and captures lock-screen PINs and patterns. It thwarts removal by intercepting uninstall confirmation and displaying fake Google Play overlays. Anti-analysis techniques include APK container tampering, a large manifest file, and invalid DEX instructions. Distribution vectors include malvertising, SMS, and phishing sites offering APK downloads outside Google Play. Researchers link the malware to Chinese threat actors based on AI prompt language.
Potential Impact
RatHat enables attackers to gain persistent, high-privilege control over infected Android devices without requiring physical access or external debugging hardware. It can steal sensitive user credentials, including banking and cryptocurrency account information, intercept SMS messages and one-time passwords, and capture lock-screen authentication data. The malware's AI-driven interface automation makes detection and removal more difficult, increasing the risk of prolonged compromise. Its persistence mechanisms ensure it can restore itself and maintain access even after partial removal attempts. The malware's ability to establish a reverse-proxy tunnel further facilitates covert command and control communications.
Defensive Guidance
No official patch or fix is available as this is malware rather than a software vulnerability. Users should avoid downloading APK files from outside Google Play unless the publisher is explicitly trusted. Accessibility permissions should not be granted to untrusted apps. Regular scanning with Google Play Protect or equivalent mobile security solutions is recommended. Users should be cautious of malvertising, SMS, and phishing sites promoting APK downloads. Due to the malware's anti-removal techniques, manual removal may be difficult and professional assistance may be required.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/","fetched":true,"fetchedAt":"2026-09-17T22:16:45.433Z","wordCount":809}
Threat ID: 6aac66cd55bf5e2cf5ff6e18
Added to database: 09/17/2026, 22:16:45 UTC
Last enriched: 09/17/2026, 22:16:50 UTC
Last updated: 09/17/2026, 22:17:07 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.