A newly discovered Android banking Trojan dubbed RatHat leverages phone capabilities for account theft. The malware can navigate an infected device, steal banking login credentials, intercept verification codes, and reconstruct a victim's screen-lock PIN or pattern. Victims receive SMS phishing messages or see malicious ads leading to fake download pages, usually appearing as familiar apps.
Unlike traditional malware, RatHat can utilize a live AI assistant to analyze interfaces and make informed decisions about where to click or scroll. This variability makes it challenging to detect using signature-based methods, potentially allowing criminals to bypass traditional security measures.
New Android Malware Utilizes AI Upon installation, RatHat persuades the victim to enable the Accessibility Service on their Android device, claiming that removing a network restriction is necessary or offering a false financial benefit. Once granted, the permission allows the app to view screen content and act on behalf of the user, much like the Android banking Trojan activity previously reported in other campaigns. Persistence increases the recovery stakes.
The design also incorporates Android threats such as fake apps, deep permissions, and remote control, including hidden work profile schemes to bypass fraud checks. Users should only install apps from Google Play or trusted official stores, be cautious of unsolicited links and ads, and reject accessibility requests that don't clearly support a genuine function.











