The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity firm Zimperium has identified a new Android malware called RatHat that is assessed to be run by China-based threat actors.
- RatHat reaches devices through smishing campaigns, malvertising, and third-party forums that trick users into installing infected APK files.
- The malware abuses Accessibility permissions and Android Debug Bridge self-pairing to escape the app sandbox and gain shell-level privileges on the device.
- RatHat can harvest SMS messages, credentials, screen content, keystrokes, and lock screen PINs, and it uses a generative AI assistant to navigate compromised devices automatically.
- The malware survives uninstallation by retaining shell access through a local service that reinstalls it, which is why users need to be wary of apps from unofficial sources.
What to watch next
- Whether more victims outside the initial targeted smishing and malvertising campaigns are affected.
- Google's response, including possible Play Protect updates or Android patches addressing the ADB self-pairing abuse.
- Further analysis of the AI-powered navigation system and other malware families adopting similar GenAI techniques.
Coverage1
1 report
English national1
All filed from India
Named China · Google · RatHat · Fernando Ortega · Gianluca Braga · Vishnu Pratapagiri · Zimperium
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
