RatHat is a newly discovered Android trojan attributed to China-based operators by Zimperium researchers, publicly disclosed on 17–18 September 2026. The malware combines an AI-powered screen-control subsystem with Android Debug Bridge (ADB) abuse and Accessibility Services hijacking to give operators deep, persistent control of compromised devices without requiring constant manual interaction.
Distributed via targeted smishing campaigns and malvertising links pointing to deceptive third-party download portals, RatHat is designed to steal banking credentials, authentication codes, and screen-lock PINs. Its most notable persistence mechanism abuses ADB to retain a shell session even after the malicious application is uninstalled by the victim.
The combination of AI-assisted device navigation, anti-removal persistence, and a financially motivated operator profile makes RatHat a significant threat to mobile banking users. The threat is assessed as actively evolving, with the smishing-led distribution model suggesting deliberate victim targeting rather than indiscriminate spray-and-pray deployment.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.