Android phones carry the stuff criminals crave most: bank apps, passwords, login codes, and the kind of personal details that can open the door to everything else. A new threat called RatHat goes after all of it, and it does it with a nasty mix of social engineering, powerful Android permissions, and AI-assisted automation. What makes it especially dangerous is how far it can burrow into a device once someone takes the bait.
Researchers say RatHat is built to do more than just spy. It can steal banking credentials, grab one-time codes, and even help rebuild a PIN or unlock pattern from touch behavior on the screen. In some cases, it can keep a foothold on the phone even after the obvious malicious app has been removed.
The attack usually starts with a trick. Investigators say the malware spreads through SMS phishing, shady ads, and fake download pages that try to pass off the malicious app as something ordinary, like a browser or streaming tool. That familiarity is the hook, because it makes people lower their guard just long enough to install an APK from outside Google Play.
Once the fake app is on the phone, RatHat pushes hard for Accessibility permission. That setting is meant to help users who need extra on-screen assistance, but it can also let an approved app inspect what is displayed and interact with the interface. RatHat uses that access to move through menus, change settings, and set up the next stage of the attack without needing constant help from the user.
From there, the malware goes after Developer Options and Wireless Debugging. It can pull the pairing code shown on the phone and connect to Android Debug Bridge on its own, which gives it a much deeper level of access than a regular app should ever have. That opens the door to shell-level control and a persistent connection back to the attacker.
AI plays a role too. RatHat can feed information from Android’s live Accessibility tree into a generative AI assistant, which helps it figure out what is on the screen, where to tap next, and when to scroll. That makes the malware less rigid and more adaptable than old-school automation that follows the same script every time.
Once inside, RatHat turns its attention to money. It can display fake overlays on top of banking and cryptocurrency apps, tricking people into typing credentials into a screen that belongs to the attacker. It also targets payment services and can intercept SMS messages and notifications to catch two-factor codes and one-time passwords before they disappear.
The low-tech-looking part is almost the creepiest. RatHat can monitor touch coordinates and compare them against known keypad layouts, which helps it infer PINs and pattern locks without ever needing to read the digits on-screen. That means the usual screen-reader protections do not necessarily help, because the malware is watching the finger movement itself.
Getting on the phone is only half the battle for RatHat. It also tries to make removal messy by canceling uninstall attempts, showing fake error messages, and leaving behind a separate native service that can survive after the visible app is gone. In some cases, it can even ask for Device Admin rights, which raises the stakes further if the phone owner tries to fight back.
Google says it has not found RatHat on Google Play based on current detection, and it says Play Protect already shields Android users from known versions of the malware. That is a useful layer of defense, especially for people who keep their app installs inside the official store and leave Play Protect switched on. It is not a reason to get careless, though, because RatHat leans heavily on installs from outside the normal path.
Staying safe starts with the basics that still work. Avoid sideloading APK files, be suspicious of unexpected texts or ad-driven download pages, and treat any request for Accessibility access as a flashing warning light. Wireless Debugging should stay off unless there is a real reason to use it, and strong antivirus software can add another layer of detection if something suspicious sneaks through.
Keeping Android and apps updated matters too, even if updates do not stop every trick RatHat uses. New patches close off old holes, and good security habits close off the rest. If a device is already showing signs of compromise, a confirmed infection deserves more than a quick delete, because leaving a hidden service behind can keep the problem alive long after the app icon is gone.
The bigger takeaway is simple: this kind of malware thrives when a phone owner is rushed, distracted, or overly trusting. A fake app, a permission prompt, or a text message that feels urgent can be enough to start the chain reaction. On Android, that single tap can become the moment a phone stops acting like a phone and starts working for somebody else.
