September 21, 2026:


Security researchers have flagged a new strain of Android malware that behaves unlike anything seen before on mobile devices.
Instead of relying on rigid, pre-programmed scripts, this threat uses artificial intelligence to decide its next move in real time, making it much harder for standard protections to catch.
Researchers at Zimperium’s zLabs team uncovered a new Android malware strain named RatHat, linked to threat actors believed to be operating out of China. The malware stands out for pairing generative AI with a multi-stage infection process, using that combination to maintain control over infected devices and pull off financial theft.
RatHat spreads mainly through targeted text message phishing and malicious advertising campaigns that direct victims toward fake third-party download pages.
Once installed, it abuses Android’s Accessibility service and pairs that abuse with the ability to independently connect to the device’s own debugging tools, letting it escape the normal boundaries that separate apps from the rest of the system.
Once RatHat gains a foothold, it builds fake login screens designed to look identical to real banking and payment apps, tricking victims into typing in their financial credentials directly into the malware’s own overlay. At the same time, it intercepts one-time passwords and two-factor authentication codes sent to the device, giving attackers what they need to slip past extra account protections.
The malware has specifically been observed targeting apps tied to global banking and payment platforms, including WeChat and Alipay, using deceptive screen overlays built directly into its code.
According to CNET, Zimperium noted that RatHat is not limited to a single device brand or version, since its techniques rely on abusing core Android system permissions and services rather than exploiting flaws unique to any particular manufacturer. Because it hides behind convincing icons and app names, sometimes disguising itself as a popular streaming app or even mimicking Chrome, spotting it visually can be difficult.
Users should watch for unexpected requests to enable Accessibility permissions, unfamiliar apps demanding Device Admin access, or a phone that suddenly behaves sluggishly or drains battery faster than usual, since these can all be signs of a hidden background process running without permission.
What separates RatHat from older mobile malware is its use of generative AI to interpret what is happening on screen and decide how to act. Rather than following a fixed script, the malware feeds a live snapshot of the device’s on-screen elements to an AI model, which then tells it exactly where to tap and what buttons to press, making its behavior far more adaptable than traditional automated malware.
Beyond that AI layer, RatHat includes a hardware-level keylogger capable of tracking raw finger movements on the screen to reconstruct PINs and unlock patterns, even when a device uses privacy protections meant to block screenshots or hide password fields.
It can also grant itself administrative-level control over a device without needing a computer, and even if a user manages to delete the main app, a hidden background service quietly reinstalls it and restores its permissions automatically.
Zimperium recommends staying cautious about installing apps from outside the official Google Play Store, particularly ones downloaded through links sent via text message or found through online ads.
Since RatHat relies heavily on tricking users into manually granting Accessibility permissions, treating any app that suddenly requests that access as a red flag is a reasonable precaution, especially if the request comes with urgent or unusual justification.
Checking for unfamiliar apps in device settings, watching for unexpected pop-ups resembling banking login screens, and keeping mobile security software active are all practical ways to catch early signs of infection before financial credentials get exposed.