Zimperium discovers RatHat Android malware leveraging AI and wireless debugging for advanced password theft.

Cybersecurity researchers at Zimperium recently discovered RatHat, a new Android malware strain linked to threat actors in China. Zimperium's zLabs reported RatHat employs novel persistence techniques and utilizes generative AI for operational control. Malwarebytes explains this unique AI use enables attackers to direct device interactions, such as tapping or scrolling, without relying on fixed scripts.

RatHat typically infects devices through social engineering. Attackers persuade targets to download what appear to be legitimate apps, like Google Chrome, from fake websites mimicking the Google Play Store. Users unknowingly install RatHat with the counterfeit app. The malware then requests accessibility permissions while disguised as a genuine program. Once granted, RatHat activates Wireless Debugging in Developer Options, using this Android feature to pair with the device. This access allows RatHat to capture text messages, create app overlays, and steal passwords.