Malware

RatHat Android malware uses AI‑driven UI automation to steal data

⏱️ 4 min read📅 9/18/2026👁️ 15 views

What makes RatHat stand out

RatHat talks to an external AI assistant, feeding it a serialized view of the Android UI so the AI can tell the malware which button to tap.

Technical walk‑through

First the app sneaks onto a device through malvertising, SMS links or phishing sites that host an APK outside Google Play. Once installed it asks for the Accessibility permission, which it then abuses to perform privileged actions.

With Accessibility enabled the malware flips on Developer Options and Wireless Debugging, giving it a local ADB‑shell context. It drops a Go‑based library named liblocal-service.so that runs commands with those shell privileges, bypasses battery‑optimisation restrictions and stays resident.

A second native library, libmedia_codec.so, acts as a reverse‑proxy client for Factory Reset Protection (FRP). It opens a persistent tunnel back to the attacker, allowing full control even after a factory reset.

Credential‑stealing tricks

RatHat paints HTML overlays on top of banking and cryptocurrency apps, tricking users into entering usernames, passwords or OTP codes. It also watches incoming SMS, notification payloads and one‑time passwords, records text‑change events, pulls URLs from browsers and even captures lock‑screen PINs, passwords and unlock patterns.

Self‑preservation

  • The Go agent can reinstall itself if a user tries to delete the library.
  • If the agent is removed, the malware can rebuild the missing components.
  • When the system shows an uninstall confirmation, RatHat intercepts the dialog, cancels the removal and shows a fake Google Play error overlay.

Evasion tactics

Analysis shows the APK is deliberately malformed: the manifest is oversized, the DEX contains pseudo‑instructions that don’t parse, and the container is tampered with. Those tricks make static scanners stumble.

Why defenders should care

Any Android device that installs an APK from an untrusted source now faces a tool that can autonomously navigate the UI, harvest credentials and stay hidden even after a user attempts removal. The AI‑driven automation removes the need for hard‑coded scripts, meaning signatures that look for specific UI flows will miss it.

Practical mitigations

  1. Block installation of apps from unknown sources; enforce Google Play as the only trusted store.
  2. Educate users that legitimate apps never ask for Accessibility permission unless absolutely required.
  3. Monitor for the presence of the two native libraries (liblocal-service.so, libmedia_codec.so) on devices.
  4. Use mobile‑device‑management (MDM) solutions to disable Developer Options and Wireless Debugging on corporate phones.
  5. Deploy endpoint‑detection tools that inspect runtime behavior, especially unexpected ADB shell commands or persistent reverse‑proxy connections.
#Android#Malware#AI#Credential Theft#Accessibility