BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked RatHat Android Malware Uses AI to Steal Data

AI-powered RatHat malware exploits Android accessibility for persistent remote control.

  • Researchers have uncovered a new Android malware called RatHat, linked to China-based threat actors, which uses AI to navigate compromised devices.
  • RatHat spreads through targeted smishing and malvertising campaigns and employs a multi-stage infection pipeline that breaks out of Android’s sandbox.
  • The malware abuses accessibility services to enable wireless debugging, extract ADB pairing codes, and deploy Go-based agents for persistent shell access.

Cybersecurity researchers have flagged a new Android malware called RatHat, assessed to be operated by China-based threat actors, that features an artificial intelligence-powered system to navigate and control compromised devices. Distributed primarily via targeted smishing and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline, according to Zimperium researchers.

- Advertisement -

Once deployed, the malware pairs Accessibility abuse with autonomous local ADB self-pairing to break out of the standard Android application sandbox. The malicious APK functions as a dropper, incorporating four anti-analysis techniques: container tampering using ZIP encryption flags, a manifest bomb that crashes automated pipelines, DEX bytecode poisoning with invalid element attributes, and dual string-encryption via Base64.

RatHat’s architecture consists of a malicious Android app, a Go agent, and an FRP reverse-proxy client. The Android app acquires accessibility services permissions, then abuses them to unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware serves overlays atop specific apps to harvest credentials, records the screen using MediaProjection API, intercepts SMS messages, and overrides installation attempts with a fake Google Play Store overlay.

Even if the victim uninstalls the app, the attacker retains shell access via a local ADB daemon. The Go Agent masquerades as a native library to execute commands, establish persistence, and apply power management exemptions. The FRP client creates a secure reverse tunnel to the C2 server, allowing attackers to collect SMS, credentials, files, lock screen PIN, screen captures, keystrokes, and installed apps—including a hardware-level keylogger that records finger presses. Zimperium noted that RatHat’s multi-tiered architecture and reliance on out-of-lifecycle daemons illustrate why traditional, signature-based mobile security controls are insufficient.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

IMF: Tokenization reshapes markets, but risks remain

The IMF warns tokenization could reshape markets but faces legal uncertainty and stability risks.Tokenized...

Justin Sun Prize winners announced but prize details unclear

Justin Sun has spent the past week announcing winners of the Justin Sun Prize,...

OpenAI publishes 722 math papers; only 162 are Lean-verified

OpenAI published 722 math manuscripts on GitHub on Tuesday, all produced by an internal...

Musk claims Indian oligarchs block Starlink launch in India

Elon Musk accused unnamed Indian oligarchs of blocking Starlink's launch to protect a "monopolistic...

SecondFi offers $7.60 per NFT in $21M hack recovery

SecondFi launched a recovery portal for victims of its $21 million Cardano wallet hack,...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading