Android malware can steal your PIN and bank logins

Security researchers have identified a new Android malware called RatHat that uses generative AI to steal banking credentials and intercept authentication codes. The malware relies on social engineering to trick users into installing malicious apps and granting deep system permissions.
Why it matters
As cybercriminals increasingly adopt AI tools, mobile security threats are becoming more sophisticated and harder for average users to detect.
Your Android phone probably holds far more sensitive information than you realize. Banking apps, passwords and security codes can all pass through that little screen in your hand. A newly uncovered Android threat called RatHat wants access to all of it. Security researchers at Zimperium discovered the malware, which uses generative AI as part of its attack, and found that it can turn permissions you approve into surprisingly deep control of your phone. RatHat can steal banking credentials, intercept authentication codes and even reconstruct a PIN or unlock pattern from where your finger touches the screen. It can also create a persistent connection that may survive after you remove the malicious app. The attack still needs help from the person holding the phone. RatHat relies heavily on tricking someone into installing a malicious Android app and approving powerful permissions.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in