A fresh Android malware Trojan, dubbed RatHat, has surfaced, predominantly aiming at users in Chinese-speaking regions and propagating via fraudulent applications. This Trojan capitalizes on Android accessibility permissions to deeply infiltrate and control devices. It forges interfaces of financial apps to pilfer account details, intercepts SMS alerts, records textual content, extracts browser URLs, and gathers sensitive information from the lock screen. The most striking aspect of RatHat is its incorporation of an AI recognition system. This system transforms device interfaces into XML format and transmits them to an AI assistant for scrutiny, thereby acquiring navigation directives to facilitate remote manipulation. Moreover, the Trojan thwarts user attempts to uninstall it and employs diverse anti-analysis techniques, heightening the challenge for security software to identify and thwart it.
