Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Who owns the customer relationship when an agent does the buying? – GeekWire

    September 22, 2026

    European neocloud Verda raises $189M to build the AI infrastructure of tomorrow

    September 22, 2026

    5 Content Syndication Networks That Capture Mindshare And Conversion

    September 22, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Latest in Tech»Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem
    Latest in Tech

    Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem

    InfoForTechBy InfoForTechSeptember 20, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Say Hello to RatHat, a New AI-Powered Malware Invading the Android Ecosystem
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    There’s a frightening new digital threat that Android users should be aware of. New AI-powered malware called RatHat can automatically gain admin-level control over your Android device, stealing whatever it wants.

    RatHat was discovered by mobile security firm Zimperium, which notes that the program tricks people into downloading what appears to be a legitimate app, such as Google Chrome, via a fake web page that mimics the Google Play Store. Once opened, the app seemingly innocently asks for accessibility permissions, which it then uses to take over your entire device. 

    RatHat uses the accessibility permissions users grant it to navigate your phone’s menu system and unlock Wireless Debugging, a legitimate developer tool commonly used in app testing, then grants itself ADB Shell permissions. This effectively grants the malware admin access to your device. Next, RatHat installs an AI-assisted agent that runs system commands to steal information and a proxy client that tunnels that stolen information back to the hacker. 

    “That sort of infection chain isn’t necessarily more complex than, say, following a phishing email on Windows and saying yes when the program asks for administrator permissions,” Sav Wheeler, a research engineer for Malwarebytes, said in an email. “Escalation in the Android landscape often relies on granting apps additional permissions that the OS locks away by default to keep the devices secure.”

    Per Zimperium, the malware can be traced to attackers in China and primarily targets apps like WeChat Pay and Alipay, which are as popular in China as Apple Pay and Venmo are in the US. Malwarebytes notes that other financial apps can also be targeted. So far, researchers have found 162 infected apps in the wild, which report back to a dozen servers run by attackers. 

    What can this malware do?

    The worrisome part is that the malware doesn’t do anything wonky the user would notice immediately, unlike with a ransomware attack. Instead, it bides its time, runs in the background, and captures information that appears on the screen, including usernames, passwords and two-factor authentication codes. 

    It can also steal raw touch input from your touchscreen, allowing it to recreate PIN codes and pattern unlock codes. It can capture SMS messages, too, thereby intercepting security codes. There isn’t much that the app can’t steal if it wants to.

    How can I find out if I have RatHat on my phone?

    The only way to find it is to run an antivirus scan that detects the software. Malwarebytes is a free option on Google Play that can do this. Wheeler told CNET that it can detect the malware pretty easily, which is good news for anyone who’s worried about whether or not they have it. 

    The bad news is that RatHat is sneaky and difficult to quarantine. 

    “Unfortunately, because of the behavior of the program itself — remasquerading as other apps, dynamically changing its behavior using the AI endpoint — static analysis and quarantining is not enough to remove the malware,” Wheeler said. 

    In short, the only way to actually get rid of this malware is a complete factory reset of your device. This effectively removes the hidden secondary files the malware installs, which antivirus apps can’t deal with. Uninstalling the app doesn’t work because the malware retains its admin access through those hidden files, which then let it reinstall the app over and over again. 

    How do I avoid RatHat?

    This is also good news. RatHat’s infection method is complex and can be thwarted at multiple points during the process. First, you should never click a link from an SMS or email from a source you don’t know or trust. That stops almost all social engineering threats right out of the gate, including RatHat. Verify that you’re using the official Google Play app rather than a deceptive imitation website. Look at the top of the screen. If it has an address bar where you type URLs, it’s just a website disguised as an app. Real apps do not have address bars.

    Also, note that preinstalled or existing versions of Chrome do not require reinstallation, so if you’re being asked to reinstall an app you know you have, think twice.

    Denying accessibility permissions is the critical final line of defense against mobile malware. While downloading a malicious application is risky, the software remains largely powerless until you grant it advanced system privileges.

    Wheeler says that SMS phishing is targeted to each specific user, so you won’t see the same phishing attempt as another person, and the tactics the app uses vary from region to region. Following standard antiphishing practices and not enabling accessibility permissions largely removes the threat of RatHat. 

    Joe Hindy


    Joe is a freelance journalist. It all started with a long-running affection for building his own PCs, which he did for the first time as a teenager. It evolved into a lifelong enjoyment of putting words on the internet about the subject. He’s written for CNET, PCMag, Mashable and SlashGear as a freelance writer, and worked as a Senior Editor at Android Authority for 10 years. When he’s not writing about tech and science, he’s learning the ins and outs of DIY home repair, gaming, playing his bass guitars and posting help on PC building and gaming subreddits. He is a staunch believer that orange juice should have pulp.

    See full bio

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Who owns the customer relationship when an agent does the buying? – GeekWire

    September 22, 2026

    David Sacks: The key adviser urging Trump not to regulate AI, explained

    September 22, 2026

    Why It’s Important To Unplug Your PC During A Power Outage

    September 22, 2026

    Napster Developing AI Teacher Clones to Provide Personalized Homework Support

    September 21, 2026

    S’pore retrenchments hit highest level since 2020 as vacancies fall

    September 21, 2026

    Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping

    September 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026375 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202634 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202622 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026375 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202634 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.