{
  "id": 8292142,
  "title": "New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead",
  "url": "https://urgent.news/2026/09/18/new-android-malware-can-deploy-ai-to-automate-device-control-and-it",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T19:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/new-android-malware-can-deploy-ai-to-automate-device-control-and-it-can-even-bring-itself-back-from-the-dead"
  },
  "original_language": "en",
  "account": "Zimperium zLabs researchers have uncovered a new Android malware named RedHat, which is capable of leveraging artificial intelligence to automate device control. Originating from China, this banking trojan operates by interpreting screen layouts in real-time, enabling it to steal credentials and evade app redesigns. Distributed through third-party app stores, social media, malvertising, and SMS spam, RedHat requires Android's Accessibility permissions to function.\n\nThis particular malware goes beyond traditional banking trojans by incorporating an AI-powered \"assistant\" that operates independently of the malware's operator. The AI model acts as a \"remote eyes and hands,\" allowing RedHat to navigate and control the victim's device without constant human intervention. Unlike most Android banking trojans, RedHat does not require pre-coded coordinates for password entry or login buttons. Instead, it captures screen images, sends them to the AI assistant, and receives instructions on how to proceed.\n\nThe AI-driven adaptability of RedHat poses a significant challenge for security software, as traditional, scripted automation becomes less effective against this malware. Zimperium's analysis revealed that RedHat utilizes advanced persistence mechanisms, including the ability to reinstall deleted components and intercept the uninstall process, displaying fake error messages to deter victims from removing the malicious software.\n\nAt present, the specific targets and the number of compromised individuals remain unknown. The emergence of RedHat highlights the evolving landscape of Android malware, where AI capabilities are increasingly being integrated to enhance malicious operations.",
  "summary": "AI can now serve as the eyes and the hands of a piece of malware and even reinstall components if they're removed.",
  "key_points": [
    "RedHat Android malware uses AI to automate device control",
    "Originates from China, distributed via multiple channels",
    "AI assistant operates independently without human intervention"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}