Find notable cyber news and cases, enriched with sources, timelines, and signals.

RatHat smishing-malvertising Android APK distribution campaign

Campaign
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishing sites promoting APK installs from outside Google Play. The malware abuses Accessibility permissions, enables Developer Options and Wireless Debugging to reach ADB shell access, and installs agents that support persistence, tunneling, and device control. Zimperium says the operation uses an AI-powered UI-automation subsystem to navigate infected devices, while also targeting banking and cryptocurrency apps for credential theft, SMS/OTP interception, and screen/input capture. It also tries to block removal and frustrate analysis with fake overlays, APK tampering, a 61MB manifest, and invalid DEX pseudo instructions.

Related Happenings

RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers

Technical Analysis
H score28 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

How related: "RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," comments Zimperium.

About this happening: RatHat is a new Android malware campaign analyzed by Zimperium zLabs and linked to China-based threat actors. It uses an AI-powered UI-automation subsystem to...

RatHat Android credential-theft malware

Malware Activity
H score27 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

How related: Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting.

About this happening: RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...

Latest development: 18.09.2026 09:17

Zimperium said RatHat pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the Android sandbox, unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware stages native daemons that execute with shell-level privileges, lets a Go Agent masquerading as liblocal-service.so apply persistence and power management exemptions, and can re-install itself through the local service after uninstall. The operator also uses an FRP reverse-proxy client to establish a persistent reverse tunnel to the C2 server, while the malware can record finger presses on screen with a hardware-level keylogger.

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

Hagaseca Android RAT spread via THost9 loader and ADB worm behavior

Malware Activity
H score19 First: 10.09.2026 17:36 Last: 10.09.2026 17:36 Sources 1

About this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...

Manic Android malware activity with offline relay exfiltration

Malware Activity
H score29 First: 20.08.2026 13:02 Last: 20.08.2026 13:02 Sources 1

About this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...

Timeline

  1. 17.09.2026 16:00 3 articles · 4d ago

    RatHat Android malware spreads through phishing lures and malicious APKs

    Initial Disclosure

    Zimperium researchers identified RatHat, a new Android malware strain linked to China-based threat actors, targeting banking credentials, notifications, 2FA/OTP data, and screen and input capture. The campaign delivers malicious APKs through deceptive phishing sites, malvertising, SMS phishing, and third-party forums, then uses a dropper with encrypted assets, SessionInstaller APIs, and anti-analysis layers to install the payload; the malware also serializes the device Accessibility tree and appears to use Google’s Gemini AI models for UI automation.

    Show sources