RatHat: China-linked Android malware uses generative AI to navigate Accessibility UI (Zimperium)
Zimperium zLabs (16 September 2026) details RatHat, an Android malware strain they link to China-operating actors. Distribution is primarily smishing and malvertising to third-party APK portals (outside Google Play). Once installed it abuses Accessibility permissions, enables Developer Options / Wireless Debugging for local ADB self-pairing, and stages native Go agents (liblocal-service.so persistence/keylogging; libmedia_codec.so FRP reverse-proxy tunnel) with shell-level privileges and mutual self-restore if either component is removed. Credential theft: banking/crypto HTML overlays, SMS/OTP interception, browser URL capture, and hardware-level reconstruction of lock-screen PIN/password/pattern from touch input. Distinctive: an AI UI-automation engine serialises the live Accessibility tree to XML and queries a generative AI assistant (unnamed in the report; prompts observed in Chinese) for element coordinates, on-screen text, and navigation actions (e.g. SCROLL_DOWN), making automation more adaptable than fixed scripts. Anti-removal: intercepts uninstall confirmation and shows a fake Google Play error overlay; anti-analysis includes bloated manifest and invalid DEX tricks. Mitigations per researchers: avoid sideloaded APKs, deny Accessibility to untrusted apps, keep Play Protect on. Wire: BleepingComputer 17 September 2026.
- Product
- Android (consumer / BYOD); banking and cryptocurrency apps targeted via overlays
- Versions
- n/a (malware family; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Do not sideload APKs from SMS/ad links; revoke Accessibility for untrusted apps; remove unknown Developer Options / wireless debugging; factory-reset if compromise suspected.
Primary: Zimperium zLabs — RatHat AI-powered Android malware (16 Sep 2026) · BleepingComputer — RatHat AI device control (17 Sep 2026)
