VibeTimes
#기술

AI-powered Android malware RatHat steals even your PIN

모민철모민철 기자· 10/3/2026, 6:05:31 AM· Updated 10/3/2026, 7:00:35 AM

RatHat, an AI-generated Android malware, steals bank login credentials and even PINs. Security firm Zimperium announced that its researchers discovered the new Android malware, which exploits Android settings such as accessibility permissions and wireless debugging to gain deep control over infected phones. The discovery is a prime example of the latest trend of generative AI being weaponized for cyberattacks.

Attackers primarily distribute the malware through SMS phishing, malicious ads and deceptive third-party download sites. The malicious APK disguises itself as familiar software such as streaming apps or Chrome, with the well-known names lowering users' guard. RatHat only works if users manually install the APK from outside the Google Play Store.

Once installed, the app requests activation of accessibility services. Depending on the region, users may be prompted with claims that it will fix network issues or provide financial benefits. While accessibility services serve legitimate functions on Android, granting them also gives an app permission to read screen content and manipulate the interface.

RatHat uses these permissions to change settings on the user's behalf. It can also steal banking credentials, intercept authentication codes, and even determine PINs or lock patterns by tracking where users tap on the screen. Furthermore, it can establish a persistent connection that survives even after the malicious app is deleted.

Zimperium explained that users have multiple chances to stop the attack. Confirmed countermeasures include avoiding installing files of unknown origin from outside Google Play and being wary of accessibility permission requests.

Related Articles