Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

AI-driven Android malware RatHat uses large language model to hijack phones

Security researchers discovered a new Android Trojan called RatHat that employs artificial intelligence to target users and steal banking and crypto credentials.

Zimperium zLabs uncovered RatHat, an Android Trojan that incorporates AI to streamline its malicious operations. The malware is spread through fraudulent advertisements, text messages and phishing webpages, delivered as an APK that bypasses the official Play Store. Analysts suspect Chinese actors because the underlying large language model processes commands in Chinese.

After infection, RatHat deploys a resilient agent that reinstalls the payload if removed and presents fake HTML pages to capture credentials for banking and cryptocurrency apps. It can read SMS messages and one-time passwords, undermining two-factor authentication, and also harvest browser links, passwords and device unlock codes. The AI component automates navigation and command execution on the compromised phone, making detection by security software more difficult.

Why it matters

AI-enabled malware raises the bar for mobile cyber-attacks, endangering users' financial and personal data.

In this story

android malwareAI-poweredRatHatlarge language modelphishingbanking credential theftSMS interceptionpersistent agentChinese-linked
Get the beta ↗