Security firm Zimperium says it has identified a new Android malware strain, RatHat, that can take over infected devices and target banking credentials. According to the company’s zLabs researchers, the malware also goes after crypto app logins and can intercept SMS one-time passcodes used during sign-ins.
The report says RatHat is distributed through smishing campaigns and malvertising that steer users to malicious APK downloads outside Google Play. Zimperium said the activity appears linked to threat actors operating in China, though that attribution remains the firm’s assessment.
How the malware gains control
Zimperium said RatHat relies on Android Accessibility permissions after installation. With those permissions, the malware can enable Developer Options and switch on Wireless Debugging, steps that let it pair with the phone’s own Android Debug Bridge service.
That pairing is significant because it allows the malware to move beyond the limits normally imposed on Android apps. In effect, the report describes RatHat as using the device’s built-in debugging features to escape the usual application sandbox and gain broader control over the handset.
Credential theft and remote access
Once active, RatHat reportedly deploys Go-based agents that can run shell commands and maintain a persistent reverse tunnel to the attackers. Zimperium said that setup gives operators a durable channel for remote control.
The malware is also designed to steal sensitive data directly from victims. Researchers said it can display fake HTML overlays on top of banking and cryptocurrency applications to capture usernames and passwords, while also intercepting SMS messages carrying one-time authentication codes.
AI-driven device navigation
A central claim in the report is that RatHat uses artificial intelligence to navigate and control an infected phone’s interface in real time. Zimperium said this makes the malware more flexible than traditional scripted automation and potentially harder for security tools to spot.
The researchers added that RatHat can monitor raw touch input from the device. That capability can be used to reconstruct PINs, passwords, and unlock patterns entered by the victim, expanding the range of information the attackers may be able to capture.
Persistence and anti-analysis features
Zimperium said RatHat is built to survive removal attempts. If a victim deletes the main application, the malware can reportedly reinstall itself through a hidden background service, allowing the infection to persist.
The report also says the malware includes several features intended to frustrate analysis. Those include a 61MB Android manifest and poisoned DEX bytecode, which researchers said are meant to disrupt security tools and make the sample harder to inspect.
What is confirmed so far
The confirmed details in the report point to a malware campaign operating outside Google Play and relying on direct APK installation through text-message lures and malicious advertising. Zimperium’s findings describe a toolset aimed at banking and crypto account access, device control, and interception of two-factor codes.
For now, the next concrete step is further analysis by mobile security researchers and platform defenders. The report provides the current public account of RatHat’s methods, while its broader reach and full operational history were not established in the source material.
Source: dailyhodl.com