Live Feeds
● LIVE Updated 1h ago Β· 9 sources tracked

Android malware can steal your PIN and bank logins

RatHat is a new Android banking trojan that employs generative AI to steal banking credentials, intercept two-factor authentication codes, and reconstruct PINs or pattern locks via touch input analysis. Discovered by Zimperium researchers, the malware requires users to install a malicious app and grant powerful permissions to function. Once active, RatHat can establish a persistent connection that may remain on the device even after the malicious application is removed. The malware's console specifically uses Gemini AI to help attackers identify and target higher-value victims.

πŸŽ™οΈ

Listen to Live Briefing

Real-time synthesized voice briefing Β· Live Feeds Desk

⏱ ~3 min
Speed:
RSS Source map (9)
⚑ Key Developments & Real-Time Context
Text size:
  • βœ“ RatHat malware can steal banking credentials and intercept two-factor authentication codes.
  • βœ“ The malware can reconstruct a user's PIN or pattern lock by analyzing touch inputs on the screen.
  • βœ“ RatHat utilizes Gemini AI to identify higher-value victims.
  • βœ“ The attack requires the user to install a malicious app and approve powerful permissions.
πŸ›‘οΈ Source Corroboration: 9 independent reporting domains (90% confidence) ⏱ Read time: ~2 min

What changed

Zimperium researchers identified RatHat's ability to use Gemini AI for victim profiling and its capacity to survive app removal.

Live updates

  1. RatHat Android Malware Uses AI to Steal Banking Credentials and PINs

    RatHat is a new Android banking trojan that employs generative AI to steal banking credentials, intercept two-factor authentication codes, and reconstruct PINs or pattern locks via touch input analysis. Discovered by Zimperium researchers, the malware requires users to install a malicious app and grant powerful permissions to function. Once active, RatHat can establish a persistent connection that may remain on the device even after the malicious application is removed. The malware's console specifically uses Gemini AI to help attackers identify and target higher-value victims.

    Why it matters

    The emergence of RatHat reflects a shift toward AI-integrated cybercrime. By combining Gemini AI with ADB shell access, attackers can automate the identification of lucrative targets and maintain deeper device control. This threat highlights the risk of social engineering where users are tricked into granting excessive permissions.

    What is confirmed

    • RatHat malware can steal banking credentials and intercept two-factor authentication codes.
    • The malware can reconstruct a user's PIN or pattern lock by analyzing touch inputs on the screen.
    • RatHat utilizes Gemini AI to identify higher-value victims.
    • The attack requires the user to install a malicious app and approve powerful permissions.
    • RatHat can create a persistent connection that may survive the removal of the malicious app.

    Still unconfirmed

    • Group-IB uncovered a banking trojan called RemControl built with AI help.

    What to watch next

    • Evidence of RatHat infections in the wild beyond research environments
    • Updates from Google regarding Android security patches to block RatHat's persistence methods
    • Confirmation of the relationship between RemControl and RatHat
    Sources used for this update (10)
    1. Fox News β€” Android malware can steal your PIN and bank logins
    2. cyberpress.org β€” RATHat Android Banking Trojan Uses Gemini AI and ADB Shell to Take Control of Devices
    3. The Hacker News β€” RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
    4. Pasquale Pillitteri β€” Group-IB uncovers RemControl, the Android banking trojan built with AI help
    5. infosecurity-magazine.com β€” RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
    6. www.foxnews.com β€” RatHat Android malware uses AI to steal bank logins and ...
    7. www.foxnews.com β€” Windows malware uses Grok AI to help stay hidden, researchers say
    8. www.cyberghostvpn.com β€” Types of Identity Theft: 13 Common Red Flags and How to Protect Yourself - CyberGhost VPN
    9. thezonerocks.com β€” Android malware can steal your PIN and bank logins
    10. usvinews.com β€” Android malware can steal your PIN and bank logins - Fox News
    confidence 90%
πŸ“Š

Community Sentiment: How do you assess this situation?

Voice your perspective Β· Real-time aggregated sentiment from the Live Feeds community