Back
zLabs uncovers RatHat Android malware with generative AI control
SiTech AI Team3 min read

zLabs uncovers RatHat Android malware with generative AI control

zLabs says RatHat is an Android malware strain linked to actors who appear to operate in China. It uses generative AI, phishing sites, Accessibility abuse and local ADB pairing to steal financial data and maintain shell-level access.

RatHat distribution and financial focus

zLabs has identified RatHat, a novel Android malware strain linked to threat actors who appear to be operating in China. It is distributed mainly through smishing and malvertising that direct users to deceptive third-party download portals. Third-party forums also promote malicious APKs presented as legitimate apps that users are urged to install manually.

RatHat uses fake banking, cryptocurrency and payment interfaces to collect financial data. Injected overlays target selected banking and crypto apps, while embedded screens target WeChat and Alipay. It captures credentials and PINs, and an SMS receiver with a notification listener can intercept OTP and 2FA codes. A generative AI engine sends the live Accessibility tree as XML to an AI assistant, which resolves text, returns coordinates for synthetic clicks and issues commands such as SCROLL_DOWN.

Local ADB breaks the app sandbox

RatHat first relies on users granting Accessibility access. Its SystemHelperService uses synthetic gestures to tap Build Number seven times, enable Wireless Debugging and read the six-digit ADB pairing code and dynamic port. With the embedded libadb-android library, the app authenticates to the device's local ADB daemon and reaches /data/local/tmp, obtaining shell-level access beyond normal app sandbox restrictions.

Through ADB, it stages liblocal-service.so, a Go agent, and libmedia_codec.so, an frpc reverse-proxy client disguised as a native library. The Go agent grants persistent operation and WRITE_SECURE_SETTINGS, applies power-management exemptions and can disable packages. The FRP client establishes a persistent tunnel to the attacker's server, providing a general-purpose route to the device's ADB daemon.

Credential theft and self-restoration

RatHat collects information through Accessibility text events, browser address-bar data and screen or input capture. Its Go-based AdbTouchCapture reads raw /dev/input data through getevent. Matching touch coordinates with keypad and pattern layouts in locateValues.json lets it infer PINs, passwords and unlock patterns, including when FLAG_SECURE, a custom keyboard or lock-screen protection hides text from accessibility.

Removal is also resisted. RatHat can cover the uninstall confirmation with a fake Google Play failure screen and cancel the action. Even if the APK is removed, local-service runs outside the package lifecycle, checks for the app and reinstalls it while restoring runtime permissions and Accessibility access. A heartbeat restores the service, scans ADB ports and re-enables debugging when needed.

Anti-analysis and remote control

A dropper carries two encrypted payload assets. Four anti-analysis layers use ZIP container tampering, a 61MB manifest dominated by undocumented chunks, invalid-width DEX pseudo-instructions and StringFog with StringCrypto encryption. A separate anti-debug layer performs six checks covering JDWP, ptrace, debug settings, Frida, Xposed, root status and emulator signals.

The app registers over HTTP and maintains a WebSocket with heartbeats, using HMAC-SHA256 authentication. The Go agent exposes a local HTTP server at 127.0.0.1:7910, maintains a separate heartbeat and buffers offline tasks. The FRP component provides a persistent reverse tunnel. zLabs says this architecture enables adaptive execution outside conventional app sandbox boundaries and can retain access after the main app is removed.

Sources: Malwarebytes · Security Affairs · Fox News

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.