# RatHat malware uses Android accessibility access to steal credentials

_Published Monday, September 21, 2026 at 9:09 PM EDT · Security · Latest · Tier 1 — Major_

![RatHat malware uses Android accessibility access to steal credentials — Primary](https://helios-i.mashable.com/imagery/articles/01NCEX5U7f1U5WofEMb9kYZ/hero-image.fill.size_1200x675.v1790030639.jpg)

Zimperium researchers identified RatHat, Android malware that uses an AI assistant and accessibility permissions to navigate infected devices, capture messages and steal passwords and multifactor authentication codes. Attackers distribute it through fake websites that imitate the Google Play Store and offer applications disguised as legitimate software.

After a user grants accessibility access, RatHat activates Android Wireless Debugging and pairs with the device. It can create credential-stealing overlays and record raw screen touches. The reported defense is to avoid untrusted downloads; an infected device requires a factory reset to remove the malware.

## Sources

- [Mashable](https://mashable.com/tech/rathat-android-malware-records-screen-touches)

---
Canonical: https://techandbusiness.org/newswire/KJFwuoOhDRE0j-QKztNWQG
Published: 2026-09-22T01:09:34.270Z
Story chronology: 2026-09-21T22:58:51.000Z
Retrieved: 2026-09-22T03:02:37.546Z
Publisher: Tech & Business (techandbusiness.org)
