Smartphones
Safety
20.09.2026 11:33

Share with others:

Share

Smart AI takes control of Android phones

Always install only the apps you need on your Android mobile device and only from official sites.
Always install only the apps you need on your Android mobile device and only from official sites.

The new RatHat malware spreads via SMS, fake advertising, and online phishing, requiring users to manually install an APK file outside of the official Google Play store. Its primary goal is to steal banking information, one-time passwords (OTPs), and cryptocurrency access. By abusing accessibility services, the Trojan automatically turns on developer options and over-the-air debugging. This provides itself with a local, elevated shell without the need for a physical connection to the computer, reminiscent of the approach of the well-known ToxicPanda and RedHook malware families.

After gaining ADB access, the Trojan installs a contained Go service called liblocal-service.so. This bypasses battery consumption limits and ensures system durability by protecting and reinstalling itself with the main program. Another component, libmedia_codec.so, acts as a reverse-proxy FRP client and establishes a permanent connection to the attackers’ servers. To steal data, the Trojan displays HTML overlays to intercept online banking logins, reads SMS messages, notifications, PIN codes, screen lock patterns, and even web addresses from the browser.

The main feature of the Trojan is the use of artificial intelligence to manage the user interface. The system converts the screen structure into XML format and sends it to a remote artificial assistant. The assistant accurately recognizes the coordinates of the buttons, reads the text and automatically executes commands such as scrolling down. This makes the operation much more flexible and less detectable than old scripts with fixed coordinates. When attempting to manually remove it, the Trojan intercepts the confirmation window, cancels the process and displays a fake Google Play Store error message.

The basic protection against new malicious code remains unchanged: avoiding unverified APK files and using Google Play Protect.


Interested in more from this topic?
information security cyber security


What are others reading?