New Android Malware Uses AI to Steal Banking Logins and Control Phones: Report

A newly uncovered Android malware strain is using artificial intelligence to take over infected phones and steal banking credentials.
Zimperium’s zLabs team says the malware, called RatHat, appears linked to threat actors that appear to be operating in China and spreads through smishing and malvertising that push malicious APK downloads outside Google Play.
Once installed, RatHat abuses Accessibility permissions to turn on Developer Options and Wireless Debugging, then pairs with the device’s own ADB service to break out of the normal app sandbox.
It deploys Go-based agents for shell commands and a persistent reverse tunnel back to attackers, while showing fake HTML overlays on banking and crypto apps to capture logins and intercept SMS one-time codes.
“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation.
The malware also monitors raw touch input to reconstruct PINs, passwords and unlock patterns, and can reinstall itself through a hidden background service if a victim tries to remove the main app.
Researchers say RatHat packs several anti-analysis tricks, including a bloated 61MB Android manifest and poisoned DEX bytecode meant to break security tools.
Follow us on X, Facebook and Telegram
Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
The post New Android Malware Uses AI to Steal Banking Logins and Control Phones: Report appeared first on The Daily Hodl.