Scam Alert:

ACTIVE SCAM ALERT

SCAM ALERT: RatHat Android Malware Uses AI to Steal Banking Credentials, PINs, and Authentication Codes

SCAM ALERT: RatHat Android Malware Uses AI to Steal Banking Credentials, PINs, and Authentication Codes

A newly analyzed Android malware strain called RatHat represents a significant development in mobile financial fraud because it combines familiar social engineering techniques with artificial intelligence, Android accessibility abuse, credential-stealing overlays, and persistent remote access to an infected phone.

RatHat does not simply wait for a predetermined screen and execute a fixed sequence of commands. Researchers found that the malware can provide information about what is displayed on an infected Android device to a generative AI system, which then helps determine where the malware should tap, scroll, or navigate. This gives the malware a degree of adaptability that traditional scripted mobile malware does not possess.

The danger is especially significant because the malware is designed to steal information directly associated with financial accounts, including banking login credentials, one-time authentication codes, payment application PINs, screen-lock information, SMS messages, and other sensitive information.

Source Credit

The SCARS Institute gratefully acknowledges Malwarebytes Labs and Malware Intelligence Researcher Pieter Arntz for bringing this threat to public attention in the September 18, 2026 report, “New Android malware uses AI to steal bank logins and PINs.” The Malwarebytes report is based on technical research conducted by Zimperium’s zLabs team, which published its detailed RatHat analysis on September 16, 2026.

What Is RatHat?

RatHat is an Android Trojan designed to compromise mobile devices and obtain extensive access to information and functions normally protected by the Android operating system.

According to Zimperium, the malware appears to be associated with threat actors operating in China, although that attribution remains an assessment rather than a confirmed identification of the people responsible. The malware has been distributed through SMS phishing, known as smishing, malicious advertising, deceptive websites, and third-party forums. Victims are directed toward websites that encourage them to download Android applications outside the normal Google Play installation process.

The malicious application may be disguised as something familiar and desirable. Researchers found versions that presented themselves as a well-known streaming application and configurations capable of appearing under labels such as Chrome.

The criminal still needs the victim to install the application. That initial act of social engineering remains one of the most important parts of the attack.

How the Attack Begins

A victim may receive a text message, encounter an advertisement, follow a link from a website, or find what appears to be an application download through another online source.

The victim is encouraged to download an APK file. APK stands for Android Package Kit and is the file format used to install Android applications.

Installing applications manually from websites rather than through an established application store is commonly called sideloading. Sideloading itself has legitimate uses, but it removes some of the protections that users receive when applications are distributed through established stores and subjected to their security processes.

RatHat then attempts to convince the victim to provide Android Accessibility Service permissions.

Accessibility Services are legitimate and important Android functions designed to help people interact with their devices. Unfortunately, the same capability that allows accessibility software to read screens and perform actions can become extremely powerful when granted to malicious software.

RatHat reportedly uses deceptive explanations to obtain this permission. In some versions, victims are told that access is required because of network restrictions or are presented with a supposed financial incentive.

Once accessibility permission has been granted, the attack changes substantially.

RatHat Can Begin Controlling the Phone

RatHat uses its Accessibility Service access to navigate Android settings automatically.

According to the researchers, it can activate Developer Options by performing the necessary taps, turn on Wireless Debugging, locate the Android Debug Bridge pairing interface, read the six-digit pairing code displayed by the device, and pair itself with the phone.

Android Debug Bridge, commonly called ADB, is a legitimate development tool. Software developers use it to communicate with Android devices, test applications, run commands, transfer information, and troubleshoot software.

RatHat turns this legitimate capability against the device owner.

Once the malware establishes its own ADB connection, it obtains a much more powerful level of access than an ordinary Android application normally possesses.

The significance is not merely technical. A victim has effectively moved from having one malicious application installed to having malicious software operating with a much deeper level of control over the phone.

The AI Component Changes How the Malware Navigates

One of RatHat’s most unusual characteristics is its use of generative AI to assist with navigation.

Traditional malware automation frequently relies upon predetermined instructions. The malware expects a particular screen element to appear in a known place and then performs a programmed action.

RatHat uses a more adaptive approach.

Zimperium found that the malware converts information from the device’s live Accessibility tree into XML and communicates with what the researchers described as one of the world’s most popular generative AI assistants. The researchers did not publicly identify the AI service in their written findings.

The AI system can help identify where a particular interface element appears, determine the text being displayed, and provide navigation instructions such as scrolling downward. The malware can then generate synthetic taps based upon those instructions.

This does not mean that an AI independently decided to steal someone’s money. Criminals built and operate the malware. The AI component is being used as another automation tool inside their attack infrastructure.

Its importance comes from adaptability. Instead of requiring every screen arrangement and interaction to be programmed in advance, RatHat can interpret aspects of what it encounters and adjust its actions.

That makes criminal automation more flexible.

How RatHat Steals Banking Credentials

RatHat monitors which applications are being used on the infected phone.

When the victim opens a targeted banking, cryptocurrency, payment, or financial application, the malware can place a fraudulent interface over the legitimate application. This technique is commonly known as an overlay attack.

The victim believes the login screen belongs to the banking application because it appears at exactly the moment the legitimate application has been opened.

The information entered into the false screen is instead captured by the criminals.

According to the research, RatHat has targeted financial applications as well as payment platforms including WeChat and Alipay. Its overlay system is capable of collecting banking usernames, passwords, and payment PINs.

The malware also monitors SMS messages and notifications.

That means stealing a password may not be enough to stop the attack.

If a bank sends a one-time password or two-factor authentication code through SMS or a notification, RatHat may capture that information as well.

RatHat Can Steal the Phone’s PIN and Unlock Pattern

One of the more troubling capabilities identified by researchers involves the way RatHat monitors physical interaction with the screen.

The malware’s native component can observe raw touch input associated with the device. Researchers found that this information can be compared with known keypad layouts or unlock-pattern arrangements.

The result is that RatHat may reconstruct the numbers or pattern used to unlock the device based upon where the user touched the screen.

This technique works differently from simply reading visible text from the screen. It examines the coordinates of the user’s physical touches and uses those positions to determine what was entered.

That potentially gives criminals access not only to financial credentials but also to one of the most important security secrets protecting the phone itself.

Removing the Malicious App May Not Remove RatHat

RatHat also contains a particularly dangerous persistence mechanism.

After obtaining deeper access through ADB, it installs separate native components that operate independently from the original Android application.

One component acts as an agent capable of executing commands with elevated privileges. Another establishes a persistent reverse-proxy connection that gives the criminals continuing remote access to the compromised device.

This separation creates an important problem.

A victim may discover the suspicious application and uninstall it, believing the infection has been removed. According to both Malwarebytes and Zimperium, the remaining background component can determine that the application has disappeared and reinstall it.

The malware can effectively restore itself. For that reason, Malwarebytes advises that a device infected with RatHat should be factory reset rather than relying upon ordinary application removal.

Warning Signs

Android users should take seriously any unsolicited message, advertisement, website, or social media promotion that instructs them to download an APK file directly.

A legitimate-looking application icon does not establish legitimacy. An application calling itself Chrome, a streaming service, a financial tool, or another familiar service can still be malicious.

An even stronger warning appears when an application asks the user to enable Accessibility Service permissions when accessibility functions are unrelated to what the application is supposed to do.

Requests to enable Developer Options or Wireless Debugging should receive even greater scrutiny. These are advanced Android features intended primarily for development and troubleshooting. Ordinary consumer applications should not require users to activate them as part of normal installation.

A person who encounters instructions telling them to disable security protections, approve unusual accessibility permissions, install software from unknown sources, or enable debugging should stop before continuing.

How Android Users Can Protect Themselves

The most effective protection begins before RatHat obtains access.

Applications should be installed through Google Play or another trusted official application source whenever possible. Users should avoid downloading APK files from advertisements, text messages, unfamiliar websites, social media posts, or unsolicited links.

Accessibility permissions deserve particular attention. Users should understand why an application requires accessibility access before approving the request.

Developer Options and Wireless Debugging should remain disabled unless the device owner has a specific technical reason for using them.

Android devices should also remain fully updated, and reputable mobile security software should be kept current.

Malwarebytes reports that Malwarebytes for Android identifies RatHat as Android/Trojan.Exploit.RatHat.

What to Do if RatHat Infection Is Suspected

A suspected RatHat infection should be treated as a potential compromise of the entire device, not merely as a suspicious application.

The affected phone should no longer be trusted for banking, cryptocurrency transactions, password changes, or other sensitive activities.

Using another trusted device, the individual should immediately contact financial institutions associated with accounts accessed from the infected phone. Passwords for important accounts should be changed from the clean device, beginning with email accounts, financial accounts, cryptocurrency services, and accounts capable of resetting other passwords.

Banks should be told that the mobile device may have been compromised by credential-stealing malware. Recent transactions, newly added payment recipients, transfers, password changes, authentication settings, and account recovery information should be reviewed.

If cryptocurrency wallets or exchanges were used on the infected device, those accounts require immediate examination as well.

Because RatHat’s persistence mechanism can survive removal of the visible application, Malwarebytes recommends a factory reset of an infected device. Important files should be handled cautiously before restoration because reinstalling questionable applications or restoring malicious components can recreate security problems.

No Public Victim or Loss Total Has Been Established

The technical research describes an active malware family and the mechanisms through which it is being distributed, but the public research reviewed by the SCARS Institute does not establish a reliable total number of infected devices or a confirmed worldwide financial-loss figure.

Users should not interpret the absence of a published victim count as evidence that the threat is insignificant.

RatHat is important because it demonstrates an advancement in the way mobile financial malware operates. Criminals are combining social engineering, legitimate Android functions, persistent remote-access mechanisms, credential overlays, hardware-level input monitoring, and generative AI into a single attack chain.

The criminal still needs an entry point. That entry point is frequently a person being persuaded to install something that should never have been installed.

The Larger Threat

Artificial intelligence is not replacing traditional scam techniques. It is being incorporated into them.

RatHat still begins with familiar methods: phishing messages, malicious advertisements, deceptive websites, fake applications, misleading permission requests, and social engineering.

What has changed is what the malware can do after those techniques succeed.

AI-assisted navigation allows criminal software to respond more flexibly to changing screens and device interfaces. Accessibility abuse allows the malware to manipulate the device. ADB abuse gives it deeper control. Credential overlays steal financial information. SMS interception captures authentication codes. Touch monitoring can reveal PINs and unlock patterns. Persistent background services allow continued access even when the victim believes the malicious application has been removed.

Each element already existed in some form.

RatHat brings them together.

SCAM ALERT KEY MESSAGE

RatHat does not infect an Android phone merely because the owner receives a text message or sees an advertisement. The attack depends heavily upon persuading the user to install a malicious application and grant permissions that the application should never possess.

  • Do not install Android applications from unsolicited links, advertisements, text messages, social media promotions, or unfamiliar download websites.
  • Do not grant Accessibility Service permissions simply because an application instructs you to do so.
  • Do not enable Developer Options or Wireless Debugging at the request of an ordinary application.

If an Android device suspected of RatHat infection has been used for banking, cryptocurrency, email, or other sensitive accounts, treat those credentials as potentially compromised and respond from a different trusted device.

The important development is not simply that criminals are now using artificial intelligence.

It is that criminals are combining AI with proven social engineering and malware techniques to make attacks more adaptive after a victim opens the door.

Source and full credit: Malwarebytes Labs, Pieter Arntz, “New Android malware uses AI to steal bank logins and PINs,” September 18, 2026. The Malwarebytes reporting is based on technical research from Zimperium zLabs published September 16, 2026.

Leave A Comment

Your comments help the SCARS Institute better understand all scam victim/survivor experiences and improve our services and processes. Thank you

Thank you for your comment. You may receive an email to follow up. We never share your data with marketers.