Cybersecurity experts have identified a new Android malware known as RatHat, which is believed to be operated by Chinese threat actors. It spreads primarily through targeted smishing and malvertising campaigns that lead to deceptive third-party download portals. Container tampering, which makes certain files appear as directories in the package or sets the ZIP general-purpose encryption flag on some files to be ignored by Android's libziparchive but not by other tools like unzip and apktool.
Manifest bomb, which triggers automated analysis pipelines to crash or time out by inserting undocumented 0x9999 chunk headers in "AndroidManifest.xml" that are skipped by the Android native runtime.
The malware also serves overlays on specific apps to harvest credentials, record the screen using the Android MediaProjection API, intercept SMS messages, and override installation attempts by presenting a fake failure overlay that mimics the Google Play Store. This AI is utilized for non-malicious purposes such as resolving named targets' center coordinates on the screen to direct synthetic clicks, extracting actual on-screen text from the XML, and signaling automatic navigation commands like SCROLL_DOWN. The C2 server commands are diverse, featuring comprehensive features that enable threat actors to gather SMS messages, credentials, files, lock screen PINs, patterns, or passwords, as well as screen captures, keystrokes (including URLs entered in web address bars), and a list of installed applications.











