$ techbeacon▋
Phishing

AI‑Driven Android Trojan ‘RatHat’ Targets Banking Apps, Hijacks Credentials and MFA Codes

AI‑Driven Android Trojan ‘RatHat’ Targets Banking Apps, Hijacks Credentials and MFA Codes

Security researchers have uncovered a novel Android banking Trojan named RatHat that leverages artificial‑intelligence techniques to automate the compromise of smartphones and exfiltrate sensitive financial data. The malware is capable of stealing login credentials, personal identification numbers and one‑time passcodes used for multi‑factor authentication, raising fresh concerns about the sophistication of mobile threats aimed at banking customers.

According to analysis by Zimperium’s zLabs team, RatHat employs AI‑powered modules to identify and interact with banking applications in real time. The malicious code can dynamically locate input fields, capture keystrokes and screen content, and then relay the harvested information to command‑and‑control servers. By automating these steps, the trojan reduces the need for manual configuration and can adapt to a wide range of banking apps across different regions.

The researchers say the trojan is distributed through a combination of repackaged legitimate apps and malicious advertising networks, allowing it to reach users who download seemingly innocuous software. Once installed, RatHat gains elevated permissions and uses obfuscation techniques to evade detection by standard antivirus scanners. Its AI component also helps it to mimic normal user behavior, making behavioral‑based defenses less effective.

While the full scope of infections remains unclear, early indicators suggest that RatHat could affect thousands of Android devices worldwide, particularly in markets where mobile banking is prevalent. The ability to intercept one‑time passcodes undermines a key security layer that many banks rely on to protect accounts, potentially enabling attackers to complete unauthorized transactions even when users employ two‑factor authentication.

Cybersecurity experts advise users to download apps only from trusted sources, keep their operating systems and security patches up to date, and consider using mobile security solutions that incorporate AI‑driven threat detection. Financial institutions are also urged to monitor for anomalous login patterns and to educate customers about the risks of installing unverified software. As threat actors continue to integrate machine‑learning capabilities into malware, the industry is likely to see a rise in similarly advanced campaigns, prompting a reassessment of defensive strategies for both users and banks.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related