Home / Technology / New AI Android Malware Hijacks Phones With Admin Access
New AI Android Malware Hijacks Phones With Admin Access
29 Sep
Summary
- RatHat malware uses AI to gain admin access via accessibility permissions.
- It spreads through fake app download pages mimicking Chrome.
- Factory reset is the only way to remove the stealthy malware.

A sophisticated new Android malware strain, dubbed RatHat, is actively spreading by masquerading as legitimate applications like Google Chrome on deceptive download pages. Discovered by Zimperium, this malware exploits accessibility permissions granted by users to automatically escalate to admin-level control, bypassing the need for further user input.
Once granted admin access, RatHat installs an AI-assisted agent capable of executing system commands to pilfer sensitive data. It can capture on-screen information, including usernames and passwords, and even record touch inputs to reconstruct PINs and pattern locks. The malware also intercepts SMS messages, compromising security codes and making it exceptionally difficult to detect and remove.
Researchers have traced the malware's origins to China, with attackers primarily targeting financial apps like WeChat Pay and Alipay. While Google Play Protect is designed to safeguard against such threats, users who sideload apps or encounter these malicious download pages remain vulnerable. Antivirus scans can detect RatHat, but a complete factory reset of the device is the sole method for complete eradication due to its persistent hidden files.
To avoid RatHat, Android users should exercise extreme caution, avoiding suspicious links from unknown sources and ensuring they download apps exclusively from the official Google Play Store. Never grant accessibility permissions to apps unless absolutely necessary and verified. Vigilance against social engineering tactics and verifying app authenticity are crucial defenses.