New RatHat Android malware uses AI to automate device control
Key Points:
- A new Android malware named RatHat has been identified, featuring an AI-powered subsystem that enables remote operators to navigate infected devices more effectively and evade detection.
- Researchers from Zimperium zLabs link RatHat to Chinese threat actors, noting its distribution via malvertising, SMS, and phishing sites promoting APK downloads outside of Google Play.
- RatHat abuses Android Accessibility permissions to perform privileged actions, including enabling Developer Options and Wireless Debugging to gain shell-level access without external devices.
- The malware employs AI to analyze the device interface in real-time, allowing adaptable navigation and control without scripted automation, making it harder for security software to detect.
- RatHat intercepts uninstall attempts with fake overlays, uses multiple anti-analysis techniques, and targets banking and cryptocurrency apps to steal credentials, highlighting the risks of installing APKs from untrusted sources.