RatHat Android credential-theft malware
Malware Activity
Summary
Hide ▲
Show ▼
The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through smishing, malvertising, third-party forums, and malicious APKs, then uses a dropper, encrypted assets, and SessionInstaller APIs to install its payload and bypass Android protections. The malware also adds persistence, anti-analysis, and AI-assisted UI automation for more reliable theft and control.
Related Happenings
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical Analysis
H score26
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
In a malware analysis published on September 16, Zimperium’s zLabs team noted a particularly interesting feature in the malicious app: a generative AI user interface-automation engine.
About this happening:
Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and cre...
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical AnalysisHow related: In a malware analysis published on September 16, Zimperium’s zLabs team noted a particularly interesting feature in the malicious app: a generative AI user interface-automation engine.
About this happening: Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and cre...
RatHat smishing-malvertising Android APK distribution campaign
Campaign
H score33
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, SMS phishing (smishing) campaigns and third-party forums.
About this happening:
A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed t...
RatHat smishing-malvertising Android APK distribution campaign
CampaignHow related: RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, SMS phishing (smishing) campaigns and third-party forums.
About this happening: A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed t...
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
MantaxOtax Android malware with ransomware and spyware control
Malware Activity
H score32
First: 10.09.2026 16:00
Last: 10.09.2026 16:00
Sources 1
About this happening:
The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can ste...
MantaxOtax Android malware with ransomware and spyware control
Malware ActivityAbout this happening: The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can ste...
Timeline
-
17.09.2026 16:00 2 articles · 2h ago
Zimperium identifies RatHat Android malware stealing banking credentials
Initial DisclosureZimperium's zLabs team identified RatHat, a new Android malware strain linked to China-based threat actors, and found it targets banking credentials, notifications, 2FA/OTP data, and screen and input capture. The malware is distributed through deceptive phishing sites, malvertising, SMS phishing, third-party forums, and malicious APKs, then uses a dropper with two encrypted assets, native SessionInstaller APIs, multiple anti-analysis layers, and an anti-debug layer; it also serializes the device's live Accessibility tree to XML and uses a generative AI assistant for UI automation.
Show sources
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00