A team of security researchers from Zimperium has shown how artificial intelligence (AI) can be used to launch a complete attack on a mobile application, from gaining full control of a phone to committing large-scale fraud. This process, which once required years of technical knowledge in areas like rooting (modifying a phone's software to gain full control) and reverse engineering, can now be initiated with just a simple request in everyday language. AI systems, such as those using frameworks like OpenClaw or Hermes, are now capable of carrying out complex hacking tasks on their own, without the need for human intervention.
Unlike traditional chatbots, which simply respond to user inputs, these AI agents are designed to plan, execute, and adjust their actions to achieve a specific goal. In the context of mobile hacking, the AI can simulate the actions of a real user by reading the phone’s screen, using accessibility features originally intended for visually impaired users. It can fill out forms, grant permissions, or create accounts just as a person would, all without interacting with the application’s servers. This makes the attack much harder to detect.
Gaining control of a phone, once a complex and risky process, is now handled automatically by the AI. Previously, rooting an Android device or jailbreaking an iPhone required finding the right software flaw for each model and hiding the modifications from the system, which could lead to device failure. Now, the AI selects the best method and applies the necessary camouflage techniques on its own. If the targeted application is not well protected, the AI might not even need to root the device. It can download the app, insert tools to monitor and alter its behavior, and then reinstall it on a real phone.
For more secure applications, the AI combines multiple techniques. It analyzes the app's code without running it to detect protective measures like obfuscation (making the code harder to understand) and anti-sabotage features. Then, it observes the app’s operation in real time using tools like Frida, which can intercept and manipulate the app's functions. Once a vulnerability is found, the AI turns it into a reusable script that can be executed simultaneously on multiple virtual devices. This means a single hacking attempt can be scaled up into a large-scale fraud operation. Even when the application is updated, the AI can quickly adapt, making the attack nearly cost-free to repeat. Zimperium has already observed this kind of automated hacking in the real world, such as with the Android banking malware known as RatHat, which can read the screen to steal sensitive information and reinstall itself after being removed.
AI-Powered Agents Demonstrate New Mobile App Hacking Techniques
AI-rewritten from original reportingHow it works
ai-hackingmobile-securityrat-hatzimperiumai-agentsfraud-automation
Original sources:
- 🇫🇷Clubic



