
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Security researchers have identified RatHat, a new Android malware strain linked to China-based actors, that uses generative AI to automate device control, steal banking credentials, and evade detection. Distributed via phishing, malvertising, and third-party app stores, RatHat abuses accessibility permissions to gain deep access and persist on infected devices.[AI generated]
Why's our monitor labelling this an incident or hazard?
The malware incorporates an AI system that autonomously controls the victim's device interface to steal banking credentials, which is a direct violation of users' property rights and causes financial harm. The AI's role is pivotal in enabling the malware to adapt to app changes and evade detection, increasing the effectiveness of the attack. The harm is realized, not just potential, as the malware is actively distributed and operational. Hence, this event meets the criteria for an AI Incident due to direct harm caused by the AI system's use in malicious activity.[AI generated]