Summary
Zimperium zLabs has published technical analysis of RatHat, a previously undocumented Android malware family linked to China-based threat actors. RatHat incorporates a generative AI subsystem that allows operators to remotely navigate compromised devices without requiring real-time human interaction. The AI component serializes the device’s live Android Accessibility tree into XML and communicates with what researchers assess is Google’s Gemini model in Mandarin to identify on-screen coordinates, extract UI element text, and execute navigation commands. RatHat also establishes a local ADB shell through Android’s Wireless Debugging feature without requiring an external computer, enabling privileged command execution that survives standard removal attempts. The malware targets banking credentials, cryptocurrency wallet passwords, one-time passwords, lock-screen PINs, and payment information through HTML overlays impersonating legitimate banking and cryptocurrency applications.
Timeline
| Date | Event |
|---|---|
| April-June 2026 | RatHat samples captured and analyzed by Zimperium zLabs; campaign attributed to China-based threat actors based on AI prompt language written in Mandarin |
| Sep 17, 2026 | Zimperium publishes full RatHat technical analysis; Bleeping Computer and additional outlets report |
What Happened
RatHat is distributed through malvertising, SMS phishing, and third-party sites offering APK downloads outside Google Play. The installer bypasses Android’s restricted settings and Accessibility Service controls using native SessionInstaller APIs, delivering its payload across a multistage infection chain that includes four anti-analysis layers and one anti-debug layer. Once installed, RatHat abuses Android Accessibility permissions to enable Developer Options and Wireless Debugging, then autonomously pairs with the Android Debug Bridge locally — achieving shell-level command execution without requiring an external computer or USB connection.
ADB access allows RatHat to install a Go-based persistence agent (liblocal-service.so) that manages execution and restoration of both itself and the main malware. A second agent (libmedia_codec.so) establishes a persistent reverse-proxy tunnel to attacker infrastructure. The two components restore each other if either is removed, creating a mutual persistence architecture that survives standard uninstall attempts. When a user attempts to remove the application, RatHat intercepts the uninstall confirmation and displays a fake Google Play overlay.
The AI-guided navigation subsystem serializes the live Android Accessibility tree into XML and sends it to an AI assistant assessed to be Google’s Gemini with prompts written in Mandarin. The AI responds with on-screen coordinates for synthetic clicks, text extracted from UI elements, and navigation commands. This allows operators to navigate the device across different Android versions and manufacturer UI customizations without writing device-specific static scripts.
Credential capture is performed through HTML overlays impersonating banking and cryptocurrency applications including MetaMask and Coinbase Wallet. RatHat also intercepts SMS messages and notifications including one-time passwords, records text-change events, extracts URLs from browser address bars, and captures lock-screen PINs, passwords, and unlock patterns through keylogging.
Domain Intelligence
zimperium.com — 60.22
zimperium.com scores in the low-trust range at 60.22. Zimperium is the mobile security research organization that discovered and analyzed the RatHat malware family.
The Trust Observatory · thetrustobservatory.com · September 18, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026