Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem
Zimperium discovered AI-powered malware RatHat that uses a fake Google Play page to gain admin rights on Android, enables Wireless Debugging, and steals passwords, 2FA codes, and payment app data. 162 infected apps and 12 attacker servers found; only a full device reset removes the threat.
- Malware masquerades as Chrome and requests accessibility permissions
- Gains admin access via ADB Shell and installs AI agent for data theft
- Targets WeChat Pay and Alipay, 162 infected apps found
- RatHat can only be removed by full smartphone reset
Read next
Security