Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats.
AI-Powered RatHat Android Trojan
Unlike traditional malware that relies on fixed scripts, RatHat offers a live AI service with access to the Android accessibility tree. The AI can review on-screen elements and decide where to tap, scroll, or input information during an attack, making it harder for conventional mobile security products to detect.
The infection process begins with social-engineering campaigns, including smishing messages and malicious advertisements. These tactics redirect users to fraudulent download pages that impersonate popular apps, such as streaming services or web browsers. Victims are persuaded to install a malicious APK from outside Google Play and other legitimate app stores.
Once installed, RatHat pressures the user into enabling the Android Accessibility Service. The malware may display fake warnings about network restrictions or claim that enabling this permission is required to receive financial benefits.
Accessibility permissions can be particularly risky because they allow apps to inspect screen content and perform actions on the user’s behalf.
After gaining accessibility access, RatHat can navigate through Android settings and enable Wireless Debugging. It reads the six-digit pairing code displayed on the device and establishes an Android Debug Bridge (ADB) connection.
While ADB is a legitimate tool developers use to test and manage Android devices, RatHat repurposes it to gain capabilities beyond what ordinary apps are allowed.
The malware creates two disguised native components after establishing the ADB session. One is a Go-based agent that executes commands on the compromised device, while the other functions as a reverse proxy, maintaining a persistent connection to attacker-controlled infrastructure.
This connection lets attackers access the device remotely while bypassing common network restrictions, including firewalls and NAT environments.
According to MalwareBytes, RatHat specifically targets financial applications with credential-harvesting overlays designed to mimic legitimate banking interfaces.
These overlays can capture usernames, passwords, card details, and one-time passwords used in multi-factor authentication. The Trojan can also intercept SMS messages, putting transaction verification codes directly within attackers’ reach.
A particularly concerning feature of RatHat is its ability to collect raw touch coordinates from the device’s input driver. This capability allows RatHat to compare these coordinates with known keypad and pattern-lock layouts, enabling it to reconstruct PINs and unlock patterns.
This technique can bypass protections designed to prevent malware from reading sensitive information directly from the screen.
Furthermore, the malware includes persistence capabilities that may enable it to reinstall or restore its components even after users remove the visible malicious application. A factory reset is recommended for suspected infections.
To protect themselves, users should install apps only from trusted sources, reject unnecessary accessibility requests, and avoid enabling Developer Options or Wireless Debugging unless they fully understand why they need those settings.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

