RatHat is a new Android malware that records your screen touches to steal passwords. Cybersecurity researchers at Zimperium recently discovered it, and they have linked it to threat actors based out of China. The malware uses AI to navigate the device in real time, and it records raw touch inputs directly on the screen.
The Malware’s Origin
Zimperium’s zLabs researchers found RatHat. The company linked the threat actors behind it to China. The malware spreads through fake websites that mimic the Google Play Store.
How It Infects a Phone
RatHat begins with social engineering. The attacker convinces a target to download a seemingly legitimate app, like Google Chrome, from a website that looks like the official store. The user downloads the app but unknowingly installs the malware.
Once the app is installed, it requests accessibility permissions while still appearing legitimate. The user provides those permissions without realizing what they are granting.
The AI Assistant
“RatHat incorporates novel techniques for persistence and leverages generative AI for operational control,” Zimperium’s zLabs researchers said in a report. Malwarebytes explains that the malware gives a live AI assistant access to the device’s accessibility tree, rather than following a hardcoded script.
The AI assistant figures out where to tap or scroll on the device. It does not follow a fixed set of instructions. This makes the malware more adaptable and harder for security software to detect.
What It Does
With accessibility permissions, RatHat activates Wireless Debugging under Developer Options and pairs with the device. That pairing gives the malware deep control over the phone.
The malware captures text messages, creates overlays on targeted apps, and steals passwords and multi-factor authentication codes. The overlays act like a keylogger, recording the user’s raw touch inputs directly on the device.
“The AI component isn’t the only unique aspect of RatHat,” Zimperium explains. The overlay records the user’s raw touch inputs directly on the device.
“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation,” Zimperium explains.
The Factory Reset Problem
There is no fix for RatHat other than a factory reset. Once the malware is installed, the device must be wiped clean.
A factory reset is the only known way to remove the malware.
What to Do
Android users should avoid any downloads from untrustworthy sources. Check the website before downloading an app, and verify the source before granting accessibility permissions.
If you suspect your device is infected, the only option is a factory reset. There is no app or security update that can remove RatHat.
The Malware’s Reach
RatHat is a sophisticated piece of malware. It combines social engineering, accessibility permissions, and real-time AI navigation. It is harder for security software to detect than traditional scripted automation.
The malware is linked to Chinese threat actors, according to Zimperium.
The Bottom Line
RatHat is a serious threat to Android users. It records everything a user touches, and it uses AI to figure out where to tap or scroll. The malware is harder to detect than traditional automation.
The fact that the only fix is a factory reset is a serious privacy concern. Users should be careful about what they download, and they should check the website before installing an app.
Here is what you should know:
- RatHat is linked to Chinese threat actors.
- It records raw touch inputs directly on the device.
- It spreads through fake websites posing as the Google Play Store.
- There is no fix other than a factory reset.
RatHat is a new strain of Android malware that combines social engineering, accessibility permissions, and real-time AI navigation. It is harder for security software to detect than traditional scripted automation, and there is no known fix other than a factory reset.
The malware is a serious privacy concern. Users should be careful about what they download, and they should check the website before installing an app.
Source material: “RatHat is a new Android malware that records your screen touches to steal passwords,” Mashable.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

