RatHat Android is a new mobile malware that combines accessibility abuse with Wireless Debugging and a productive AI assistant. It targets passwords, PINs, and one-time codes from banking and cryptocurrency apps.

Research by Zimperium's zLabs team, published on September 16, 2026, describes an attack designed to bypass standard Android defenses. The researchers link the operators to China, as they detected Chinese incitement in requests to the AI model, but do not provide details about a specific group.
See also: RedHook Android: Malware that exploits ADB Wireless Debugging
How RatHat Android works
Distribution is mainly via targeted SMS messages, malicious ads, and websites offering APKs outside of Google Play. The file may appear as a streaming app, browser, or financial service. Once installed, RatHat Android attempts to convince the user to enable the accessibility service, using localized HTML pages and deceptive promises.
With this permission, the malware opens Developer Options, taps the build number seven times, and enables Wireless Debugging. It then reads the six-digit pairing code and ADB port from the screen, allowing it to connect to the local Android daemon without the need for a computer or USB cable.
This connection gives RatHat Android access to a shell environment with enhanced capabilities. One component, disguised as liblocal-service.so, can bypass battery restrictions, keep its services active, and disable or remove other packages. A second component, libmedia_codec.so, acts as a reverse tunnel to the operators' server.

Artificial intelligence finds the right spots
The most unusual feature is the way RatHat Android automates navigation. The malware converts the accessibility tree of the live screen into XML and sends it to a productive AI assistant. The model can detect a button, return its coordinates, read text, or suggest the next scroll.
So the operation is not based solely on fixed routes and predefined locations. It can adapt to different application and device layouts, which makes it difficult to detect by solutions that look for simple automation scenarios. Zimperium points out that the AI is used for operational control and not as an independent “brain” that decides goals.
See also: Android banking trojans: ToxicPanda 2.0 and GoldDigger expand their reach
The goal is to steal data from banking, stock exchange and payment apps, including WeChat and Alipay. RatHat displays fake forms on top of the regular apps and captures usernames, passwords, card details and PINs. It also reads SMS and notifications to intercept OTP codes and two-factor authentication.
Shell access also allows the tracking of screen touches. Using coordinates and different keyboard layouts, the malware attempts to reconstruct PINs and unlock patterns. It can also collect addresses from browsers, screen content, and elements of installed applications.

Durability and protection measures
RatHat Android is not limited to the initial installation. The independent service can remain active after the application is removed, reinstalling the APK and restoring accessibility permissions. The malware also interferes with the uninstallation window and displays a fake Google Play failure message so that the user believes that the process did not complete.
Zimperium does not mention a specific number of victims or limit the threat to a specific Android version or device manufacturer, meaning users should treat the incident as a social engineering campaign and not as a simple vulnerability in a specific app.
See also: Ads on Meta platforms promote Android Trojan StreamRat
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The SecNews technical team recommends not installing APKs from ads, SMS or unknown pages and to carefully consider any request for accessibility permissions. Enable Google Play Protect, keep Android updated and immediately remove apps that ask you to enable Developer Options or Wireless Debugging without a clear reason.
The technical details and metrics of the campaign are included in Zimperium zLabs' analysis, while BleepingComputer confirms ADB abuse, password theft, and the role of artificial intelligence. Careful application installation remains the most important defense for users.
