Researchers describe RatHat, an Android trojan linked to China-based operators, that spreads via smishing, malvertising, and fake app stores to trick people into installing a malicious APK. Once installed, it pushes for Accessibility permissions and then uses that access to take deep control of the phone, steal credentials (including banking/PINs), and intercept SMS 2FA codes.
Key findings
- RatHat is distributed via phishing sites promoted through malvertising, smishing, and forums, pushing victims to manually install a malicious APK.
- The malware’s “weak point” is needing Accessibility Service access to start; it then automates actions on-screen to escalate control.
- It targets banking/payment apps with fake overlays and also intercepts SMS messages for 2FA codes to enable account takeover.
- It uses a generative-AI-driven UI automation loop to identify on-screen elements and decide where to click, making it more adaptable than older scripted Android RATs.
Who’s being targeted
- Commonly targeted roles: All employees (mobile device users), Finance teams (higher risk of banking/account compromise), Executives and frequent travelers (heavy mobile usage).
- Affected industries: Banking and financial services, Payments and digital wallets, General consumers / mobile users.
- Attack channels: smishing, website.
- Impersonated: A legitimate app / app store, A legitimate-looking Android app.
Awareness takeaways
- Treat ‘install this APK’ links as suspicious, only install apps from official app stores approved by your organization.
- Do not grant Accessibility permissions unless the app clearly needs it for an obvious accessibility function, and verify with IT/security when unsure.
- Be alert to credential/PIN prompts that don’t look quite right, attackers can place fake screens (‘overlays’) on top of real banking/payment apps.
- SMS-based 2FA codes can be stolen on an infected phone; use stronger MFA methods where available and report unexpected SMS/code prompts.
Red flags to watch for
- Asks you to install an APK manually (outside Google Play).
- Link leads to a “fake app store” / third-party download site.
- High-pressure language like “required update” without verification.
- An app requests Accessibility permissions without a clear, necessary reason.
- Permission request appears during “setup” without explaining why it’s needed.
- The app’s behavior implies hidden control (e.g., unexpected navigation/automation).
Read the video transcript
You get a text: “Your app update is required, install the latest version from our app store here.” Looks normal, right? Behind that link is RatHat: a fake app store pushing a malicious APK. Once you install it, it begs for Android Accessibility access so it can tap, swipe, and read your screen for you. Here’s the nasty part: with Accessibility, RatHat uses an AI-driven loop to click through your phone, drop fake banking overlays, and silently grab PINs, passwords, and even SMS 2FA codes. Your move: if any text or site tells you to download an APK or grant Accessibility, stop and call IT before you tap anything.