A new Android malware named RatHat has been discovered, known for its advanced capabilities and difficulty in removal. Security researchers from Zimperium have identified RatHat as a highly automated threat that leverages artificial intelligence (AI) to perform complex tasks on infected devices. This malware spreads through deceptive methods such as fake SMS messages, malicious ads, or fraudulent download websites. Once installed, it exploits Android's accessibility features to enable wireless debugging and obtain an ADB pairing code, which allows it to open a shell session on the device, modify protected system settings, and grant itself additional permissions. RatHat uses generative AI to understand and interact with the user interface of infected apps. This allows it to adapt to different screen layouts, menu structures, and labels across various Android versions and manufacturers. The AI enables the malware to navigate apps autonomously, without relying on pre-programmed instructions. This adaptability makes it particularly dangerous, as it can bypass traditional security measures and continue operating even when the user interface changes. The malware is capable of overlaying fake login forms on banking and payment applications to steal user credentials. It can also intercept SMS messages and notifications to capture two-factor authentication codes, and monitor user inputs on the device. RatHat can directly read touch events from the screen, allowing it to determine which keys are pressed based on finger coordinates. For example, if a user is entering a PIN or a pattern lock, the malware can deduce the digits or pattern by analyzing the position of the touch points, even without seeing the actual screen content. RatHat includes a local agent that runs independently of the original APK file. If the infected app is removed, the malware can detect its absence and automatically reinstall itself, restore accessibility services, and regain its permissions without user interaction. While Zimperium has not specified the exact countries affected or the number of infected devices, the malware is believed to target international financial institutions and is attributed to actors based in China. If you suspect your device is infected with RatHat, it is crucial to disconnect from the internet and stop using the phone for sensitive activities like banking. Change passwords from a different, secure device, revoke any active sessions, and contact your bank if credentials or payment codes might have been compromised. The most reliable way to eliminate the malware is to factory reset the device, which will remove all malicious components.