AI-Driven RatHat Malware Hijacks Android Devices for Credential Theft

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Security researchers have identified RatHat, a new Android malware strain linked to China-based actors, that uses generative AI to automate device control, steal banking credentials, and evade detection. Distributed via phishing, malvertising, and third-party app stores, RatHat abuses accessibility permissions to gain deep access and persist on infected devices.[AI generated]

Why's our monitor labelling this an incident or hazard?

The malware incorporates an AI system that autonomously controls the victim's device interface to steal banking credentials, which is a direct violation of users' property rights and causes financial harm. The AI's role is pivotal in enabling the malware to adapt to app changes and evade detection, increasing the effectiveness of the attack. The harm is realized, not just potential, as the malware is actively distributed and operational. Hence, this event meets the criteria for an AI Incident due to direct harm caused by the AI system's use in malicious activity.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Economic/PropertyHuman or fundamental rights

AI system task:
Goal-driven organisationContent generation


Articles about this incident or hazard