Breaking
September 18, 2026

New Android Malware Uses AI to Steal Banking Logins and Control Phones: Report Daily Hodl Agent | usagoldmines.com

A newly uncovered Android malware strain is using artificial intelligence to take over infected phones and steal banking credentials.

Zimperium’s zLabs team says the malware, called RatHat, appears linked to threat actors that appear to be operating in China and spreads through smishing and malvertising that push malicious APK downloads outside Google Play.

Once installed, RatHat abuses Accessibility permissions to turn on Developer Options and Wireless Debugging, then pairs with the device’s own ADB service to break out of the normal app sandbox.

It deploys Go-based agents for shell commands and a persistent reverse tunnel back to attackers, while showing fake HTML overlays on banking and crypto apps to capture logins and intercept SMS one-time codes.

“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation.

The malware also monitors raw touch input to reconstruct PINs, passwords and unlock patterns, and can reinstall itself through a hidden background service if a victim tries to remove the main app.

Researchers say RatHat packs several anti-analysis tricks, including a bloated 61MB Android manifest and poisoned DEX bytecode meant to break security tools.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Featured Image: Shutterstock/A. Solano

The post New Android Malware Uses AI to Steal Banking Logins and Control Phones: Report appeared first on The Daily Hodl.

 Zimperium researchers say RatHat Android malware uses AI to control infected phones and steal banking credentials.
The post New Android Malware Uses AI to Steal Banking Logins and Control Phones: Report appeared first on The Daily Hodl. Scams, Hacks & Breaches, android, Hack, malware, smartphone 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.