Find notable cyber news and cases, enriched with sources, timelines, and signals.

RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers

Technical Analysis
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and creating new detection challenges. The sample also abuses SessionInstaller APIs, Accessibility Service protections, and four anti-analysis layers plus one anti-debug layer to improve installation success and evade inspection. The finding adds reusable intelligence on how the malware steers screens, hides its behavior, and harvests credentials and 2FA/OTP data.

Related Happenings

RatHat Android credential-theft malware

Malware Activity
H score29 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

How related: Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.

About this happening: The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through *...

RatHat smishing-malvertising Android APK distribution campaign

Campaign
H score33 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

How related: RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, SMS phishing (smishing) campaigns and third-party forums.

About this happening: A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed t...

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

Hagaseca Android RAT spread via THost9 loader and ADB worm behavior

Malware Activity
H score19 First: 10.09.2026 17:36 Last: 10.09.2026 17:36 Sources 1

About this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

Timeline

  1. 17.09.2026 16:00 2 articles · 2h ago

    Zimperium analyzes RatHat Android malware with AI-assisted UI automation

    Technical Analysis Update

    Zimperium’s zLabs identified RatHat, a new Android malware strain linked to China-based threat actors that steals banking credentials, notifications, 2FA/OTP data, and screen or input content. The sample uses a generative AI user interface-automation engine, serializes the target device’s live Accessibility tree to XML, and appears to use Google’s Gemini AI models for operator-controlled navigation and clicks while relying on four anti-analysis layers and one anti-debug layer, plus a dropper with two encrypted assets and SessionInstaller API abuse.

    Show sources