AI-driven Android malware RatHat uses large language model to hijack phones
Security researchers discovered a new Android Trojan called RatHat that employs artificial intelligence to target users and steal banking and crypto credentials.
Zimperium zLabs uncovered RatHat, an Android Trojan that incorporates AI to streamline its malicious operations. The malware is spread through fraudulent advertisements, text messages and phishing webpages, delivered as an APK that bypasses the official Play Store. Analysts suspect Chinese actors because the underlying large language model processes commands in Chinese.
After infection, RatHat deploys a resilient agent that reinstalls the payload if removed and presents fake HTML pages to capture credentials for banking and cryptocurrency apps. It can read SMS messages and one-time passwords, undermining two-factor authentication, and also harvest browser links, passwords and device unlock codes. The AI component automates navigation and command execution on the compromised phone, making detection by security software more difficult.
Why it matters
AI-enabled malware raises the bar for mobile cyber-attacks, endangering users' financial and personal data.
In this story
