# Zimperium reports RatHat malware using AI to navigate Android devices

_Published Thursday, September 17, 2026 at 8:10 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![Zimperium reports RatHat malware using AI to navigate Android devices — Primary](https://www.bleepstatic.com/content/hl-images/2024/05/03/Android.jpg)

Zimperium zLabs reported a new Android malware family, RatHat, that uses an AI-powered subsystem to remotely navigate compromised devices.

Researchers said it is distributed through malvertising, SMS, and phishing sites promoting APKs outside Google Play, and they linked it to Chinese-language operators after finding LLM prompts written in Chinese. The malware abuses Accessibility permissions, enables Developer Options and Wireless Debugging for local ADB-level execution, and installs a Go-based agent that persists even if the main payload is removed.

It can overlay banking and cryptocurrency apps, intercept SMS and one-time passwords, and capture lock-screen credentials. Zimperium said RatHat serializes the Accessibility tree into XML and sends it to an unnamed popular AI assistant for navigation instructions, making control more adaptable than scripted automation.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/)

---
Canonical: https://techandbusiness.org/newswire/UoQk6AUajDj_ae7ch1VLvV
Published: 2026-09-18T00:10:42.005Z
Story chronology: 2026-09-17T21:50:26.000Z
Retrieved: 2026-09-18T09:43:51.882Z
Publisher: Tech & Business (techandbusiness.org)
