New Android Malware RatHat Uses AI to Steal PINs and Bank Logins
Security researchers at Zimperium have uncovered RatHat, an Android malware that uses generative AI to steal banking credentials, intercept authentication codes, and reconstruct PINs from touch coordinates. The malware relies on social engineering and can persist even after the visible app is removed.
Security researchers have uncovered a new Android threat that can steal banking credentials, intercept authentication codes, and even reconstruct a user's PIN or unlock pattern from the way their finger touches the screen. The malware, called RatHat, was discovered by researchers at the mobile security firm Zimperium, who found that it uses generative AI as part of its attack and can turn permissions a user approves into deep control of the device.
RatHat spreads primarily through SMS phishing, malicious advertising, and deceptive third-party download sites, according to Zimperium. The malicious installation file, known as an APK, may pose as familiar software such as a streaming app or the Chrome browser. The download page can look convincing enough to lower a victim's guard, but the attack depends on the user manually installing the app from outside Google Play.
Once installed, the malicious app pushes the user to enable Android's Accessibility Service. The excuse can vary by region. In some cases, the malware claims the permission will solve a network problem or unlock a financial benefit. Accessibility services perform important legitimate functions on Android, but they can also give an approved app the ability to inspect what appears on the screen and interact with the interface. RatHat takes advantage of that power to begin changing settings without the user doing the work.
After gaining Accessibility access, RatHat can tap through Android settings to enable Developer Options and Wireless Debugging. It can then read the six-digit ADB pairing code displayed on the phone and connect to the device's own Android Debug Bridge. No separate computer is needed to complete the connection. ADB, short for Android Debug Bridge, gives developers powerful tools to test and manage Android devices. RatHat abuses that legitimate feature to establish shell-level access outside the normal Android app sandbox.
From there, the malware launches a Go-based agent that can execute system commands. It also starts a reverse-proxy client that creates a persistent connection back to the attacker. Zimperium says that connection can give an operator continued access to the phone's ADB service. RatHat also brings AI into the process. The malware sends information from Android's live Accessibility tree to a generative AI assistant. The AI can help determine where an item appears on the screen, read displayed text, and tell the malware when to scroll. That makes the attack more adaptable than automation that follows the same fixed sequence every time.
After gaining access, RatHat can watch for financial apps and display fake screens over legitimate ones. Those overlays can trick users into entering banking credentials directly into a page controlled by the attacker. Zimperium found RatHat targeting banking and cryptocurrency apps. It also specifically identified overlays aimed at payment services such as WeChat and Alipay. The malware can intercept SMS messages and notification content as well, giving attackers another way to capture one-time passwords and two-factor authentication codes.
Then there is the way RatHat watches fingers. The malware can monitor raw touch coordinates and compare those locations with known keypad layouts. That allows it to reconstruct PINs from where a user taps. It can use a similar method to recover Android pattern-lock sequences. Because the malware reads those touch coordinates at a low level, protections that normally hide PIN digits from screen readers do not stop this technique. That means a criminal may never need to see a PIN displayed as text. Finger movements can give it away.
RatHat also tries to make leaving the phone much harder than getting onto it. Zimperium found that the malware can interfere when a user tries to uninstall the malicious app. It can cancel the real uninstall process and place a fake Google Play error message on top of the screen. Even if the visible app is successfully removed, another problem remains. RatHat launches a separate native service outside the normal app life cycle. That service can stay behind after the original app disappears. It can then reinstall the malware and restore its permissions.
Zimperium also found that RatHat can request Device Admin rights. Those rights give it additional control, including the ability to wipe the device if someone tries to uninstall it. That persistence is why deleting a suspicious app may not be enough once RatHat fully compromises a phone. The findings highlight how generative AI is making mobile malware more flexible and harder to detect, and they underscore the importance of avoiding sideloaded apps and scrutinizing permission requests.
6



