{"slug": "rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal", "title": "RatHat is a new Android malware that records your screen touches to steal passwords", "summary": "Cybersecurity researchers at Zimperium's zLabs discovered a new Android malware strain called RatHat, linked to threat actors based in China, that uses generative AI to control an infected device's accessibility tree and steal passwords and multi-factor authentication codes. According to Malwarebytes, \"RatHat gives a live AI assistant the keys to the accessibility tree of the infected device,\" letting attackers decide where to tap or scroll rather than follow a hardcoded script. RatHat spreads via fake Google Play Store sites that trick users into installing a malicious app, then requests accessibility permissions and activates Android's Wireless Debugging feature; the only removal method is a factory reset.", "body_md": "# RatHat is a new Android malware that records your screen touches to steal passwords\n\n[Matt Binder](https://mashable.com/author/matt-binder)\n\n[Read Full Bio](https://mashable.com/author/matt-binder)\n\nBeware: There's a new malware making the rounds and it's targeting your Android device.\n\nCybersecurity researchers at Zimperium recently [__discovered__](https://www.cnet.com/tech/services-and-software/rathat-malware-attacks-android-phones/) a new strain of Android malware, called RatHat, and have linked it to threat actors based out of China.\n\n\"RatHat incorporates novel techniques for persistence and leverages generative AI for operational control,\" Zimperium's zLabs researchers said in [__a report__](https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts).\n\n**You May Also Like**\n\nAs the cybersecurity firm [__Malwarebytes__](https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins) explains, \"RatHat gives a live AI assistant the keys to the accessibility tree of the infected device.\" This unique weaponization of AI allows the attacker to figure out \"where to tap or scroll, rather than following a hardcoded script.\"\n\nAs with most malware, RatHat initially infects the device through social engineering tactics. The attacker convinces a target to download a seemingly legit app, such as Google Chrome, through a fake website posing as the Google Play Store. The user downloads the app but unknowingly installs the RatHat malware on their device.\n\n[Terms of Use](https://www.ziffdavis.com/terms-of-use)and\n\n[Privacy Policy](https://www.ziffdavis.com/ztg-privacy-policy).\n\nFrom there, RatHat requests accessibility permissions while still masked as a legitimate application.\n\nOnce the target provides RatHat with those permissions, the malware activates Wireless Debugging under Developer Options. RatHate weaponizes this actual Android developer feature to pair with the device.\n\nWith this access, RatHat is able to capture text messages and create overlays on targeted apps, steal passwords, and multi-factor authentication codes in the process.\n\n\"RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation,\" Zimperium explains.\n\nHowever, the AI component isn't the only unique aspect of RatHat. The overlay acts like a keylogger, recording the user's raw touch inputs directly on the device.\n\nAndroid users should protect themselves from RatHat by avoiding any downloads from untrustworthy sources. Unfortunately, once RatHat has infected a device, the only way to remove it is to factory reset the device.\n\nTopics\n[Android](https://mashable.com/category/android)\n[Cybersecurity](https://mashable.com/category/cybersecurity)", "url": "https://wpnews.pro/news/rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal", "canonical_source": "https://mashable.com/tech/rathat-android-malware-records-screen-touches", "published_at": "2026-09-21 22:58:51+00:00", "updated_at": "2026-09-21 23:53:04.659543+00:00", "lang": "en", "topics": ["artificial-intelligence", "generative-ai", "ai-agents"], "entities": ["RatHat", "Zimperium", "zLabs", "Malwarebytes", "Android", "Google Play Store", "Google Chrome", "China"], "alternates": {"html": "https://wpnews.pro/news/rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal", "markdown": "https://wpnews.pro/news/rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal.md", "text": "https://wpnews.pro/news/rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal.txt", "jsonld": "https://wpnews.pro/news/rathat-is-a-new-android-malware-that-records-your-screen-touches-to-steal.jsonld"}}