
Recent security reports revealed the emergence of a new malicious software called “RatHat,” which targets the Android operating system and uses artificial intelligence techniques to control infected devices and steal sensitive data.
According to the report published by the Malwarebytes website, the software relies on an intelligent assistant capable of analyzing screen content and accurately determining click and scroll locations, bypassing traditional fixed programming commands.
Attacks often begin via phishing text messages or misleading ads that direct users to fake download pages impersonating popular apps, such as streaming services or the Chrome browser, urging them to install APK files from outside the official Google Play store.
Once a device is compromised, the software exploits Accessibility privileges, along with abusing the Wireless Debugging feature associated with the Android Debug Bridge tool, giving attackers extensive control over the phone.
The danger of “RatHat” lies in its ability to record screen touch coordinates and compare them with keyboard layouts and lock patterns, to recover passcodes or patterns to unlock the device, as well as steal bank account data and two-factor authentication codes.
To avoid infection, experts recommend that Android users refrain from installing external application files received through messages or advertisements, and refrain from granting “access” powers or activating wireless patching to any untrusted applications.