Security News

New 'RatHat' Android Malware Uses AI to Steal Banking Details

Infosecurity Magazine · 17 Sept 2026
Key Takeaway Only download apps from official app stores and be cautious of links in unsolicited texts or ads, as sideloaded apps remain a top pathway for mobile banking malware.

Security researchers at Zimperium have identified a new Android malware family called RatHat, designed to steal banking credentials, notifications, and two-factor authentication codes from infected devices. The malware is spread through phishing websites, malicious advertising, SMS phishing messages, and third-party app forums, tricking victims into manually installing fake apps that look legitimate.

Once installed, RatHat uses a multi-stage process to bypass Android's built-in security protections, including restricted settings and Accessibility Service safeguards, giving it access to sensitive system functions. It also includes several layers designed to evade security analysis and debugging tools, making it harder for researchers and antivirus software to detect.

A notable feature of RatHat is its use of a generative AI tool to help automate actions on the infected device by reading and interpreting the screen's layout. Researchers noted that communications with the AI tool were conducted in Mandarin, one of several clues pointing to threat actors likely based in China. The findings, published by Zimperium's zLabs team, highlight how attackers are beginning to weave AI capabilities into mobile malware operations.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.