RatHat Android malware uses AI for adaptive control
🛡️ Zimperium zLabs discovered RatHat, an Android malware that leverages an AI-powered subsystem to remotely navigate compromised devices. Distributed via malvertising, SMS, and phishing sites hosting APKs, RatHat abuses Accessibility permissions to enable Developer Options and Wireless Debugging. It installs a Go-based agent for ADB-level commands, persistence, and self-restoration, and a second agent for persistent FRP reverse-proxy tunnels. The malware overlays HTML on banking and crypto apps, intercepts SMS and notifications, captures credentials and unlock patterns, and uses anti-analysis techniques to evade detection.
