A new Android malware named RedHat has been discovered, and it stands out because it includes an AI assistant that helps it operate independently, without needing real-time instructions from its creators. This malware was identified by security researchers at Zimperium zLabs, who believe it may have originated from China. It spreads through third-party app stores, social media, malicious advertisements, and SMS spam. To function, it requires Android’s Accessibility permissions, which normally assist users with disabilities but can also be exploited by malware.
RedHat is classified as a banking trojan, a type of malicious software designed to steal financial information. When a victim opens a banking app, the malware creates an invisible overlay that captures login credentials and one-time passwords, allowing attackers to gain control of the victim's banking accounts. What makes RedHat unique is its use of an AI-powered component, which acts like a remote "eyes and hands," enabling it to interact with the phone autonomously.
Most banking trojans rely on hard-coded screen layouts to function, which can fail if the banking app changes its design. RedHat, however, uses AI to analyze the screen, send images to the AI assistant, and receive instructions on how to proceed. This adaptability makes it more difficult for security software to detect and neutralize the malware effectively.
In addition to its AI capabilities, RedHat includes advanced features to ensure it remains on the device. It can reinstall itself if deleted and can intercept the uninstall process, displaying a fake error message to prevent users from successfully removing it. At this time, there is no public information about the specific targets of RedHat or how many people may have been affected by it.
Android Malware RedHat Uses AI to Evade Detection and Steal Banking Credentials
AI-rewritten from original reportingHow it works
androidmalwareaibanking-trojansecuritychina



