Zimperium, the pioneer in AI-empowered mobile security, announces that its zLabs research team has uncovered RatHat, an advanced Android malware strain linked to threat actors believed to be operating in China. RatHat uses generative AI to adaptively navigate compromised devices, steal financial credentials and maintain persistent control even after a user attempts to uninstall the malicious application.
Distributed through smishing, malvertising and deceptive third-party download sites, RatHat disguises itself as a legitimate application and uses a multistage infection process to evade analysis. Once installed, it abuses Android Accessibility services to enable wireless debugging and autonomously pair with the device’s Android Debug Bridge (ADB). This allows the malware to break out of the standard application sandbox and execute commands with elevated privileges.