RatHat Android Malware Uses AI to Steal Bank Logins and 2FA

RatHat Android Malware Deploys Google Gemini to Target High-Value Victims

A sophisticated new Android threat designated as RatHat utilizes generative artificial intelligence to automate attacks and sort infected devices by financial value, according to security researchers at Zimperium and Cleafy. Fox News reported that the malware targets banking applications by employing deceptive sideloading techniques and abusing powerful system privileges. While Google stated that Play Protect automatically defends users against known versions, security analysts warn that the malware’s persistent architecture requires extreme removal procedures.

RatHat primarily propagates through social engineering vectors, including SMS phishing, malicious advertising, and fraudulent download pages masquerading as familiar software like Google Store. Once an unsuspecting user manually installs the malicious APK outside the official application marketplace, the software immediately prompts for Android Accessibility Service permissions. Sideloading remains the core vulnerability exploited by these campaigns, requiring attackers to convince targets to bypass standard operating system defenses.

RatHat uses Gemini AI to manipulate system settings

Granting Accessibility access permits RatHat to manipulate system settings autonomously. The malware enables Developer Options and Wireless Debugging, reading the ADB pairing code to establish a shell-level connection outside the normal application sandbox. Security researchers noted that when built-in tap instructions fail due to varying manufacturer interfaces, the malware queries Google’s Gemini AI model directly from the phone using an internal API key to determine where to tap.

RatHat Android Malware Uses AI to Steal Bank Logins and 2FA
Photo: The Hacker News

Cleafy’s analysis of the malware’s web console revealed that operators have utilized a malware-as-a-service model with nearly 100 deployments since April 2026. The latest iteration of the control infrastructure queries Gemini to analyze intercepted text messages, estimating individual bank balances to sort infected phones into high-value and mid-value operational groups. Despite using generative AI to prioritize victims and move through screens, security firms emphasize that the model does not execute unauthorized financial transfers directly.

Financial Credential Theft and Persistent Evasion Mechanics

Inside an infected device, RatHat deploys deceptive overlay screens over banking apps to harvest login credentials, including bank logins, PINs and authentication codes. Intercepted SMS notifications and authentication codes are continuously relayed back to the attacker’s web console.

Removal proves challenging because RatHat implements aggressive persistence mechanisms. The software can leave behind a persistent service after the visible app is removed. Zimperium confirmed that this native service can automatically restore the application and its permissions, occasionally requesting Device Admin rights capable of initiating a remote factory wipe if removal is detected.

RatHat Android Trojan Uses AI to Control Devices: How AI-Powered Malware Threatens Android Users

Common Questions About the RatHat Malware Threat

How does RatHat infect an Android device?

RatHat infects devices when users manually install malicious APK files distributed via text message phishing, fraudulent online advertisements, or deceptive third-party download websites. The malware relies entirely on the user sideloading the application and manually approving Android Accessibility permissions.

What role does generative artificial intelligence play in the attack?

According to Cleafy and Zimperium, the malware uses Google Gemini both on the device to move through unfamiliar interface layouts and on the command console to analyze stolen text messages, estimating target bank balances to help operators prioritize high-value victims.

Does Google Play currently host applications containing RatHat?

Google informed security researchers that it has not found RatHat on Google Play based on current detection mechanisms, adding that Google Play Protect automatically guards Android users against known versions of the malware.

What is the recommended recovery procedure for a compromised phone?

Because RatHat deploys background services capable of reinstalling the malware after a standard application deletion, security analysts recommend performing a factory reset on any confirmed infected device after securing important data from an unaffected machine.

Frequently Asked Questions About Android Security and Malware

How can users verify if Google Play Protect is enabled?

Users can verify their status by opening the Google Play Store application, tapping their profile picture, selecting Play Protect, and opening Settings to ensure that “Scan apps with Play Protect” remains turned on.

Why do attackers target Android Accessibility permissions?

Accessibility services provide legitimate tools for users with disabilities, but malicious applications abuse these privileges to inspect screen contents, automate interface taps, and modify system developer settings without manual intervention.

Does updating the Android operating system prevent RatHat infections?

While operating system and application updates patch vulnerabilities, security analysts emphasize that updates alone cannot block RatHat because its primary vector relies on social engineering, manual sideloading, and explicit user permission grants.