Thursday, October 8, 2026 SourcesAbout🌓
🇺🇸 US ▾
BREAKING
› Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials› Podcast: One country musician is calling for other artists to oppose assault rifles› Bidets save you money and reduce waste — we tested the best options out there› 50+ products to make your life easier and our planet cleaner› Mother's Day is around the corner. Here are 50+ thoughtful gifts she'll love› A head-to-toe guide of how men should dress this spring, and where they should shop› 42 of the most useful travel products you can buy on Amazon› The 7 best high-yield savings accounts of April 2023› Taxes are due tomorrow. Here's how to file for an extension› Composting is an easy way to reduce food waste. Here's how to do it› Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials› Podcast: One country musician is calling for other artists to oppose assault rifles› Bidets save you money and reduce waste — we tested the best options out there› 50+ products to make your life easier and our planet cleaner› Mother's Day is around the corner. Here are 50+ thoughtful gifts she'll love› A head-to-toe guide of how men should dress this spring, and where they should shop› 42 of the most useful travel products you can buy on Amazon› The 7 best high-yield savings accounts of April 2023› Taxes are due tomorrow. Here's how to file for an extension› Composting is an easy way to reduce food waste. Here's how to do it
Technology

RatHat is a new Android malware that records your screen touches to steal passwords

Mashable ·
RatHat is a new Android malware that records your screen touches to steal passwords

Beware: There's a new malware making the rounds and it's targeting your Android device.

Cybersecurity researchers at Zimperium recently discovered a new strain of Android malware, called RatHat, and have linked it to threat actors based out of China.

"RatHat incorporates novel techniques for persistence and leverages generative AI for operational control," Zimperium's zLabs researchers said in a report .

As the cybersecurity firm Malwarebytes explains, "RatHat gives a live AI assistant the keys to the accessibility tree of the infected device." This unique weaponization of AI allows the attacker to figure out "where to tap or scroll, rather than following a hardcoded script." As with most malware, RatHat initially infects the device through social engineering tactics.

The attacker convinces a target to download a seemingly legit app, such as Google Chrome, through a fake website posing as the Google Play Store.

The user downloads the app but unknowingly installs the RatHat malware on their device.

SEE ALSO: Malware found hidden inside popular 'Meccha Chameleon' game maps From there, RatHat requests accessibility permissions while still masked as a legitimate application.

Once the target provides RatHat with those permissions, the malware activates Wireless Debugging under Developer Options.

RatHate weaponizes this actual Android developer feature to pair with the device.

With this access, RatHat is able to capture text messages and create overlays on targeted apps, steal passwords, and multi-factor authentication codes in the process.

"RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," Zimperium explains.

However, the AI component isn't the only unique aspect of RatHat.

The overlay acts like a keylogger, recording the user's raw touch inputs directly on the device.

Android users should protect themselves from RatHat by avoiding any downloads from untrustworthy sources.

Read the full article on Mashable ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on mashable.com — the content belongs to Mashable.

More from Mashable

See all ›

More in Technology

See all ›