Fox News image for Android malware can steal your PIN and bank logins - Fox News

💻 Technology · Fox News

Android malware can steal your PIN and bank logins - Fox News

From Fox News via USVI News: RatHat Android malware uses AI to steal banking credentials, intercept two-factor authentication codes and reconstruct your PIN from touch inputs.

USVInews.com User Network Contributor

Kurt Knutsson, the CyberGuy, details an ‘unprecedented cyber incident’ in which an OpenAI experimental AI model escaped during a security test and autonomously hacked a rival AI startup. Knutsson warns that this event proves AI safety cannot be solved by individual companies in secret and highlights the urgent need for robust guardrails and regulation.

Your Android phone probably holds far more sensitive information than you realize. Banking apps, passwords and security codes can all pass through that little screen in your hand. A newly uncovered Android threat called RatHat wants access to all of it.

Security researchers at Zimperium discovered the malware, which uses generative AI as part of its attack, and found that it can turn permissions you approve into surprisingly deep control of your phone. RatHat can steal banking credentials, intercept authentication codes and even reconstruct a PIN or unlock pattern from where your finger touches the screen. It can also create a persistent connection that may survive after you remove the malicious app.

The attack still needs help from the person holding the phone. RatHat relies heavily on tricking someone into installing a malicious Android app and approving powerful permissions. That gives you several opportunities to stop it before the malware takes over.

AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION

Missed CyberGuy LIVE? Watch the replay and discover five ways AI can help you get better healthcare.

Our free CyberGuy LIVE class Get Better Healthcare With AI has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.

Watch the free replay + downloadable checklist now at CyberGuyLive.com

RatHat abuses powerful Android settings such as accessibility permissions and wireless debugging to gain deeper control of an infected phone. (Brent Lewin/Bloomberg via Getty Images)

How RatHat Android malware gets onto your phone

That familiar name can lower your guard. A download page might look convincing enough to make you think you are installing a normal app. However, RatHat relies on you manually installing an APK outside Google Play. Once installed, the malicious app pushes you to enable Android's Accessibility service.

The excuse can vary by region. In some cases, the malware claims the permission will solve a network problem or unlock a financial benefit. Accessibility services perform important legitimate functions on Android. However, they can also give an approved app the ability to inspect what appears on your screen and interact with the interface. RatHat takes advantage of that power to begin changing settings without you doing the work yourself.

How RatHat uses AI to gain deeper access

Once RatHat gets Accessibility access, it can tap through Android settings to enable Developer Options and Wireless Debugging. It can then read the six-digit ADB pairing code displayed on the phone and connect to the device's own Android Debug Bridge. No separate computer has to complete the connection. ADB, short for Android Debug Bridge, gives developers powerful tools to test and manage Android devices.

RatHat abuses that legitimate feature to establish shell-level access outside the normal Android app sandbox. From there, the malware launches a Go-based agent that can execute system commands. It also starts a reverse-proxy client that creates a persistent connection back to the attacker. Zimperium says that connection can give an operator continued access to the phone's ADB service. RatHat also brings AI into the process.

The malware sends information from Android's live Accessibility tree to a generative AI assistant. The AI can help determine where an item appears on the screen, read displayed text and tell the malware when to scroll. That makes the attack more adaptable than automation that follows the same fixed sequence every time. We recently saw another Android threat abuse Wireless Debugging in a similar way. RatHat adds AI-assisted navigation and another persistence mechanism to the mix.

RatHat can steal bank logins and security codes

This article is republished through the USVI News affiliate desk. Reporting, analysis, and viewpoints are those of the original publisher and do not necessarily reflect USVI News.

Read more at Fox News