Zimperium finds RatHat: AI-powered Android malware steals passwords and 2FA codes
Security researchers at Zimperium discovered RatHat, AI-powered Android malware that disguises itself as legitimate apps like Google Chrome. Once granted admin rights, it gains ADB shell access, runs a background AI agent and sends passwords, 2FA codes, messages and photos to hackers via a proxy; removing it requires a full factory reset.
- RatHat disguises itself as Google Chrome and requests admin permissions
- It uses ADB shell access to run a background AI snooping agent
- Steals passwords, 2FA codes, messages and photos via a proxy client
- Full removal requires a factory reset of the device
Read next
Security