← All briefs
Brief·5 sources18 Sept 2026

RatHat Android Trojan Uses AI To Automate Credential Theft

malwaremobile-threatscredential-theftai-threatsnation-state

Summary

RatHat is a newly discovered Android trojan attributed to China-based operators by Zimperium researchers, publicly disclosed on 17–18 September 2026. The malware combines an AI-powered screen-control subsystem with Android Debug Bridge (ADB) abuse and Accessibility Services hijacking to give operators deep, persistent control of compromised devices without requiring constant manual interaction.

Distributed via targeted smishing campaigns and malvertising links pointing to deceptive third-party download portals, RatHat is designed to steal banking credentials, authentication codes, and screen-lock PINs. Its most notable persistence mechanism abuses ADB to retain a shell session even after the malicious application is uninstalled by the victim.

The combination of AI-assisted device navigation, anti-removal persistence, and a financially motivated operator profile makes RatHat a significant threat to mobile banking users. The threat is assessed as actively evolving, with the smishing-led distribution model suggesting deliberate victim targeting rather than indiscriminate spray-and-pray deployment.

Timeline

  1. 18 September 2026
    Follow-on coverage expands technical picture
    SecurityAffairs, The Hacker News, and Malwarebytes Labs published additional analysis, detailing the ADB persistence mechanism, AI-driven screen navigation, and smishing-led distribution chain.
  2. 17 September 2026
    RatHat disclosed by Zimperium researchers
    Zimperium published a technical breakdown of RatHat, attributing the malware to China-based operators. BleepingComputer and InfoSecurity Magazine carried initial public coverage on the same day.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

RatHat Android Trojan Uses AI To Automate Credential Theft | Deltabridge