NewsTradingSentimentEventsCommunityBriefing
Tech

RatHat Malware Steals Android Credentials Using AI Automation

By Tech Desk · · 2 min read
A stylized smartphone displaying a generic lock icon and a shield symbol.
Illustration: Tradingbird, based on a photo published by CNET

New AI-driven malware targets Android users by hijacking accessibility permissions to steal financial data and credentials.

Key points

  • RatHat malware uses AI to automate the theft of passwords, PINs, and financial data from Android devices.
  • The malware gains admin access by tricking users into granting accessibility permissions via a fake app download.
  • Removing RatHat requires a full factory reset, as standard uninstallation methods fail to eliminate hidden administrative files.

Android users face a sophisticated new threat known as RatHat, a piece of malware that leverages artificial intelligence to seize control of devices. Unlike traditional viruses that may demand immediate ransom, RatHat operates silently in the background, capturing sensitive information such as passwords, two-factor authentication codes, and touch inputs for PINs. The primary goal is to drain financial applications like WeChat Pay and Alipay, posing a severe risk to digital assets.

The infection process begins with social engineering, where victims are tricked into downloading a fake version of a legitimate app, such as Google Chrome, via a deceptive website that mimics the official store. Once installed, the app requests standard accessibility permissions. Users are often unaware that granting this access allows the software to navigate the phone’s system menus, unlock developer tools, and grant itself administrative privileges, effectively handing over the keys to the device.

Automated data theft techniques

Once it has admin access, RatHat installs an AI-assisted agent that executes system commands to harvest data. It captures everything displayed on the screen, including usernames, passwords, and security codes sent via SMS. Additionally, the malware records raw touchscreen inputs, allowing it to reconstruct pattern unlock codes and PINs. This data is then tunneled through a proxy client to servers controlled by the attackers, a process that is largely invisible to the user.

Security experts note that this infection chain is not uniquely complex but exploits a common vulnerability in how Android manages permissions. The malware relies on the user’s willingness to grant additional rights to an app, bypassing the security barriers that normally keep third-party software isolated. Researchers have identified 162 infected apps in the wild, primarily targeting users in China, though other financial apps remain at risk globally.

Removal requires full device reset

Detecting RatHat is possible through standard antivirus tools, with Malwarebytes cited as a free option capable of identifying the threat. However, removing it presents a significant challenge. Because the malware hides secondary files and retains administrative access, simply uninstalling the app is insufficient. It can reinstall itself using the hidden permissions it previously secured. The only guaranteed method of removal is a complete factory reset of the device, which wipes all data and settings.

Prevention relies on user caution

Avoiding RatHat requires vigilance during the download process. Users should never install apps from links sent via SMS or email from untrusted sources. It is crucial to verify that downloads come from the official Google Play Store application rather than a website. A simple visual check can prevent infection: legitimate mobile apps do not have address bars where users type web addresses, while fake store websites do. Sticking to official channels and ignoring unsolicited links remains the most effective defense against this type of threat.

Based on reporting by CNET, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories