Digital transformation

Warning: New Android malware steals bank PINs.

Phan Van Hoa September 22, 2026 07:48

A new Android malware called RatHat can steal PINs, passwords, authentication codes, and maintain access to the phone even after the user has deleted the malicious app.

Security researchers have just discovered RatHat, an Android malware targeting banking users with the ability to spoof interfaces, steal credentials, and, most importantly, maintain self-access on the device.

According to researchers at Zimperium, a cybersecurity company, RatHat exploits several built-in Android features, including disability support and developer mode, to gain deeper control over the phone.

Ảnh minh họa234
Illustrative image.

Researchers believe the hacking group behind this malware appears to be operating from China.

Not just stealing bank passwords.

The RatHat distribution campaign began with fake download sites promoted through phishing messages, malicious advertisements, and third-party forums.

Users are tricked into downloading an Android installer (APK) that looks like a legitimate app. The app then instructs the victim to grant accessibility permissions, a feature Android provides to help people with disabilities interact with their devices.

When granted this permission, RatHat can monitor screen activity, read SMS messages and notifications containing one-time authentication codes (OTPs), and collect information about installed applications.

This means the risk extends beyond simply stealing login credentials. Attackers could collect more data necessary to access bank accounts or carry out unauthorized transactions.

The malware persists even after the user deletes the application.

Most worryingly, RatHat is designed to remain active even after users uninstall the app.

The malware may display a fake uninstallation screen. But even if the user successfully uninstalls the application, a local component of RatHat may still persist outside the application's normal lifecycle.

It continuously checks if the application package still exists. If it detects that it has been deleted, this component can reinstall the APK and restore the necessary permissions without requiring the user to re-grant them in the usual way.

This means that simply removing a malicious app isn't enough to resolve the issue. Users may see the app disappear from their phone, while the attacker still has a way to maintain access and reintroduce malware to the device.

AI is being used to control infected phones.

RatHat also uses fake web interface layers that look like banking, cryptocurrency, or payment applications.

When a user opens the target application, the malware can overlay a fake interface on top of the real screen to collect login information and PIN codes.

RatHat simultaneously tracks the coordinates of touch gestures on the screen. This allows it to deduce the digits the user enters on the PIN keypad or how the user draws a pattern to unlock the phone.

Ảnh minh họa235
A new Android malware called RatHat can steal PINs, passwords, and authentication codes, and maintain access to the phone even after the user has deleted the malicious app. (Image: Internet)

Notably, researchers discovered that RatHat sends a live map of the phone's interface to a generated AI assistant to perform a number of automated tasks. The AI ​​can help the malware identify a specific button, read on-screen content, or decide when to scroll a page.

This approach allows RatHat to adapt to different interfaces and languages ​​instead of relying entirely on fixed touch locations. This is an indication that AI could become a supporting component for malware campaigns on mobile devices.

What can users do to prevent this?

To minimize the risk of malware attacks, users should exercise caution from the moment they install applications. Only download applications from official stores and avoid clicking on suspicious links sent via text messages or unwanted advertisements. In particular, do not grant Accessibility permissions to applications that do not actually need this functionality.

Users should also regularly check the permissions and features enabled on their phones. If they notice unusual notifications, strange login screens, or unexplained transactions, they should contact the bank using another trusted device to check their account.

Banks and payment service providers need to strengthen their detection of transactions made from devices exhibiting unusual behavior, such as applications overlaying the screen, interfering with phone operation, or activating developer features. For high-risk transactions, customers may be required to provide further verification before completion.

Users should also not rely solely on OTP codes sent via SMS to protect their accounts. RatHat is designed to intercept and read messages containing authentication codes, thereby creating more opportunities for attackers to gain access to accounts.

Phan Van Hoa