N E U R A L   X P E R T

RatHat Android Trojan Uses AI for Automation

The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion.

Neural Xpert

Security
RatHat Android Trojan Uses AI for Automation

RatHat Android Trojan Uses AI for Automation

A newly discovered Android trojan relies on generative AI to more intelligently navigate and control infected devices, mobile security company Zimperium reports.

Dubbed RatHat, the malware has been distributed through smishing and malvertising, relying on an automated multi-stage infection pipeline to break out of Android’s application sandbox and gain shell-level execution.

RatHat contains typical mobile malware capabilities: it steals users’ credentials, mimics banking and payment applications, and establishes a covert communication channel with its command-and-control server.

Unlike other mobile threats, it also uses generative AI to navigate and control the device interface in real time, and monitors input at the hardware level to reconstruct PIN codes, passwords, and patterns.