RatHat Android Trojan Uses AI for Automation

https://www.securityweek.com/wp-content/uploads/2024/11/android-banking-malware.png

A newly discovered Android trojan relies on generative AI to more intelligently navigate and control the infected devices, mobile security company Zimperium reports.

Dubbed RatHat, the malware has been distributed through smishing and malvertising, relying on an automated multi-stage infection pipeline to break out of Android’s application sandbox and gain shell-level execution.

RatHat contains typical mobile malware capabilities: it steals users’ credentials, mimics banking and payment applications to steal credentials and access codes, and establishes a covert communication channel with the command-and-control (C&C) server for remote access.

Unlike other mobile threats, however, it also uses generative AI to navigate and control the device’s interface in real time, and monitors users’ input at the hardware level to reconstruct PIN codes, passwords, and patterns. It also grants itself administrator-level permissions to access system functions, and installs a separate hidden background service to reinstall itself and restore its permissions.

The AI prompts...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more