RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and creating new detection challenges. The sample also abuses SessionInstaller APIs, Accessibility Service protections, and four anti-analysis layers plus one anti-debug layer to improve installation success and evade inspection. The finding adds reusable intelligence on how the malware steers screens, hides its behavior, and harvests credentials and 2FA/OTP data.
Related Happenings
RatHat Android credential-theft malware
Malware Activity
H score29
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.
About this happening:
The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through *...
RatHat Android credential-theft malware
Malware ActivityHow related: Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.
About this happening: The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through *...
RatHat smishing-malvertising Android APK distribution campaign
Campaign
H score33
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, SMS phishing (smishing) campaigns and third-party forums.
About this happening:
A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed t...
RatHat smishing-malvertising Android APK distribution campaign
CampaignHow related: RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, SMS phishing (smishing) campaigns and third-party forums.
About this happening: A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed t...
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
Timeline
-
17.09.2026 16:00 2 articles · 2h ago
Zimperium analyzes RatHat Android malware with AI-assisted UI automation
Technical Analysis UpdateZimperium’s zLabs identified RatHat, a new Android malware strain linked to China-based threat actors that steals banking credentials, notifications, 2FA/OTP data, and screen or input content. The sample uses a generative AI user interface-automation engine, serializes the target device’s live Accessibility tree to XML, and appears to use Google’s Gemini AI models for operator-controlled navigation and clicks while relying on four anti-analysis layers and one anti-debug layer, plus a dropper with two encrypted assets and SessionInstaller API abuse.
Show sources
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00