RatHat smishing-malvertising Android APK distribution campaign
Campaign
Summary
Hide ▲
Show ▼
A RatHat distribution campaign is pushing malicious Android APKs through malvertising, smishing, and deceptive phishing sites, widening the pool of users exposed to credential theft. The operation increases risk because victims are being steered into manual installs that deliver spyware designed to capture banking data, 2FA/OTP keys, and screen activity.
Related Happenings
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical Analysis
H score26
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
In a malware analysis published on September 16, Zimperium’s zLabs team noted a particularly interesting feature in the malicious app: a generative AI user interface-automation engine.
About this happening:
Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and cre...
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical AnalysisHow related: In a malware analysis published on September 16, Zimperium’s zLabs team noted a particularly interesting feature in the malicious app: a generative AI user interface-automation engine.
About this happening: Researchers exposed RatHat as an Android malware strain with a generative AI user interface-automation engine, expanding operator control over infected devices and cre...
RatHat Android credential-theft malware
Malware Activity
H score29
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
How related:
Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.
About this happening:
The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through *...
RatHat Android credential-theft malware
Malware ActivityHow related: Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.
About this happening: The RatHat Android malware is stealing banking credentials and 2FA/OTP keys from infected devices, raising account-takeover risk for mobile users. It spreads through *...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
Timeline
-
17.09.2026 16:00 2 articles · 2h ago
RatHat Android malware spreads through phishing lures and malicious APKs
Initial DisclosureZimperium researchers identified RatHat, a new Android malware strain linked to China-based threat actors, targeting banking credentials, notifications, 2FA/OTP data, and screen and input capture. The campaign delivers malicious APKs through deceptive phishing sites, malvertising, SMS phishing, and third-party forums, then uses a dropper with encrypted assets, SessionInstaller APIs, and anti-analysis layers to install the payload; the malware also serializes the device Accessibility tree and appears to use Google’s Gemini AI models for UI automation.
Show sources
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data — www.infosecurity-magazine.com — 17.09.2026 16:00