Android Trojan RatHat Uses AI to Steal Banking PINs

Security researchers at Zimperium zLabs have identified a novel threat targeting Android smartphones: the RatHat banking trojan. The malware utilizes an integrated artificial intelligence component to autonomously execute on-screen actions and harvest sensitive login credentials, multi-factor authentication codes, and PINs.

How RatHat Takes Over Smartphones

Devices are infected via smishing messages (SMS phishing), manipulated online ads, and counterfeit versions of streaming apps as well as the Chrome browser. So far, researchers have tracked 162 infected applications and twelve command-and-control servers, with traces pointing to China. Unlike conventional dangerous Android malware, RatHat relies on autonomous interaction patterns.

Once installed, the trojan gains access to Android’s accessibility services. The malware uses these permissions to enable Wireless Debugging, autonomously generates a six-digit pairing code, and establishes an ADB (Android Debug Bridge) session, granting RatHat extensive administrative privileges. Through an additional Go-based agent and a reverse proxy, the malware specifically targets banking apps.

Targeted Attacks on Financial and Payment Services

The integrated AI analyzes the operating system’s accessibility tree—the internal hierarchy of all visible UI elements—and independently decides when to swipe or tap. According to security reports, RatHat can even reconstruct PINs based on recorded touch coordinates. By deploying fake screen overlays and automating background reinstalls, the malware secures persistent access to the compromised device.

See also  Google Warns of Active Exploitation of Modem Vulnerability in Pixel Smartphones

In addition to traditional banking and cryptocurrency apps, the attacks primarily target popular Asian payment services such as WeChat Pay and Alipay. While threats like the Arcane malware have previously stolen extensive user data, deploying autonomous agents to bypass two-factor authentication elevates the threat landscape to an unprecedented level.

Google’s Countermeasures and Security Sandbox

In response to threats posed by autonomous malware, Google is developing an Android security sandbox designed to regulate the behavior of AI agents. A multi-layered security framework has already been announced for Gemini agent features in Chrome. This includes the “User Alignment Critic,” a verification model for action evaluation, alongside “Agent Origin Sets” to restrict website access. Critical actions, including financial transactions and banking operations, strictly require explicit user confirmation.

Additionally, Google released the Agent Development Kit (ADK) for Kotlin in version 1.0. This developer toolkit supports on-device AI via LiteRT-LM and ML Kit, enabling app developers to secure sensitive actions using the requireConfirmation function.

What Affected Users Can Do

Security vendor Malwarebytes is now able to detect the trojan. However, according to researchers, a device that has been fully infiltrated by RatHat can only be cleaned through a complete factory reset. To prevent infection in the first place, smartphone owners should never download app installation packages from SMS links or suspicious sources, and should avoid granting unnecessary accessibility permissions to apps in Android settings.

Sources: Borncity.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top