RatHat Lures Users to Install Fake Android Apps

Security Affairs · High sophistication
Last updated September 18, 2026

Researchers describe RatHat, an Android trojan linked to China-based operators, that spreads via smishing, malvertising, and fake app stores to trick people into installing a malicious APK. Once installed, it pushes for Accessibility permissions and then uses that access to take deep control of the phone, steal credentials (including banking/PINs), and intercept SMS 2FA codes.

Key findings

  • RatHat is distributed via phishing sites promoted through malvertising, smishing, and forums, pushing victims to manually install a malicious APK.
  • The malware’s “weak point” is needing Accessibility Service access to start; it then automates actions on-screen to escalate control.
  • It targets banking/payment apps with fake overlays and also intercepts SMS messages for 2FA codes to enable account takeover.
  • It uses a generative-AI-driven UI automation loop to identify on-screen elements and decide where to click, making it more adaptable than older scripted Android RATs.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile device users), Finance teams (higher risk of banking/account compromise), Executives and frequent travelers (heavy mobile usage).
  • Affected industries: Banking and financial services, Payments and digital wallets, General consumers / mobile users.
  • Attack channels: smishing, website.
  • Impersonated: A legitimate app / app store, A legitimate-looking Android app.

Awareness takeaways

  • Treat ‘install this APK’ links as suspicious, only install apps from official app stores approved by your organization.
  • Do not grant Accessibility permissions unless the app clearly needs it for an obvious accessibility function, and verify with IT/security when unsure.
  • Be alert to credential/PIN prompts that don’t look quite right, attackers can place fake screens (‘overlays’) on top of real banking/payment apps.
  • SMS-based 2FA codes can be stolen on an infected phone; use stronger MFA methods where available and report unexpected SMS/code prompts.

Red flags to watch for

  • Asks you to install an APK manually (outside Google Play).
  • Link leads to a “fake app store” / third-party download site.
  • High-pressure language like “required update” without verification.
  • An app requests Accessibility permissions without a clear, necessary reason.
  • Permission request appears during “setup” without explaining why it’s needed.
  • The app’s behavior implies hidden control (e.g., unexpected navigation/automation).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a text: “Your app update is required, install the latest version from our app store here.” Looks normal, right? Behind that link is RatHat: a fake app store pushing a malicious APK. Once you install it, it begs for Android Accessibility access so it can tap, swipe, and read your screen for you. Here’s the nasty part: with Accessibility, RatHat uses an AI-driven loop to click through your phone, drop fake banking overlays, and silently grab PINs, passwords, and even SMS 2FA codes. Your move: if any text or site tells you to download an APK or grant Accessibility, stop and call IT before you tap anything.

Similar attacks

Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026
RatHat Smishing Lure Pushes Android Sideloading

RatHat Smishing Lure Pushes Android Sideloading

Researchers described an Android Trojan (“RatHat”) that starts with scam texts or malicious ads and tricks people into installing a fake app from a bogus download page. After installation, it pressures victims to grant Accessibility permissions using fake excuses or incentives, then uses those…

September 18, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026