Urgent.News

What's breaking now, across thousands of outlets.

Tech

RatHat is a new Android malware that records your screen touches to steal passwords

New malware called RatHat is targeting Android devices.

RatHat is a new Android malware that records your screen touches to steal passwords

A new Android malware called RatHat has emerged, posing a significant threat to users' privacy and security. Zimperium's cybersecurity researchers have unearthed this malicious software, attributing it to threat actors from China. RatHat sets itself apart from other malware variants due to its innovative techniques for persistence and the integration of generative AI for operational control.

Malwarebytes describes RatHat as granting a live AI assistant access to the device's accessibility tree, enabling the attacker to determine specific user actions such as tapping or scrolling, rather than relying on a predefined script. This AI-powered manipulation of the Android system heightens the malware's capabilities and makes it more challenging for security software to detect.

The infection process typically begins with social engineering tactics, where the attacker persuades the target to download a seemingly legitimate app from a counterfeit website that mimics the Google Play Store. Once downloaded, users unknowingly install the RatHat malware onto their device.

To gain access to the device, RatHat requests accessibility permissions, which the unsuspecting user grants. Upon receiving these permissions, the malware activates Wireless Debugging under Developer Options, allowing it to pair with the device. With this access, RatHat can capture sensitive information such as text messages and create overlays on targeted applications, ultimately stealing passwords and multi-factor authentication codes.

What makes RatHat particularly insidious is its use of AI to navigate the device interface in real-time, making its operations more adaptable and harder for security software to detect compared to traditional, scripted automation. Additionally, the malware functions as a keylogger, recording the user's raw touch inputs directly on the device.

To protect themselves from RatHat, Android users should strictly avoid downloading apps from untrustworthy sources. If a device has already been infected, the only solution is to perform a factory reset to remove the malware.

Written by urgent.news from Mashable's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at mashable.com →

More in Tech

Lex Friedman Brings Back Strategery

I first recommended Strategery back in May 2009 , including a link to Friedman’s review at Macworld . I described it thus: Strategery is a beautiful $2 Risk-like strategy game for the iPhone.

More from Monday 21 September →