Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Bank pins and logins being stolen through new Android malware

A new Android-based malware has been discovered being deployed to steal PINs and bank details.

Tue, 22 Sep 2026
Bank pins and logins being stolen through new Android malware

The trojan malware, which is being referred to as RatHat, was analysed by researchers at Zimperium’s zLabs.

RatHat works through an automated, multi-stage infection process that grants a live AI assistant access to an infected device. Unlike traditional trojan malware, it doesn’t follow a hardcoded set of instructions, but instead uses the AI assistant to determine whether it needs to tap or scroll.

Like many other traditional malicious programs however, it abuses Android Debug Bridge (ADB) which is a legitimate tool that allows Android devices and computers to communicate. This allows the malware to escape app sandboxes and wreak havoc.

 
 

As explained in Malwarebytes’ blog, threat actors use SMS phishing - or smishing - techniques, as well as fake, malicious adverts to lure victims into going to fake download pages that disguise themselves as legitimate download pages for popular apps and tools.

As a user goes to download the fake app, it sideloads a malicious Android Package Kit (APK), and requests the user to allow access to Android’s Accessibility Service, stating it relates to a financial incentive or a “network restriction issue.” This service runs in the background and can inspect screen activity and interact with programs.

At this point, the malware turns on the debugging service, pairs with the device without a person or computer.

“This is a known, legitimate Android feature (normally used by app developers to test on a phone over Wi-Fi) that RatHat repurposes for self-escalation,” Malwarebytes says.

This then allows the malware to drop to payloads, one being the AI agent that can run system commands and a client that connects to the attackers server, bypassing Network Address Translation and Firewalls.

Finally, the virus creates overlays for targeted apps, allowing it to steal logins, track multi-factor authentication and steal one-time passwords.

It can also record screen coordinates of phone touch strokes, meaning it can reconstruct PIN codes and unlock patterns.

Malwarebytes advises that users should only ever download apps from the official Google Play store, which reduces the chances of downloading malicious programs. They also highlighted the danger of an app asking to enable Accessibility Service, Wireless Debugging or Developer options unless the reason for the app needing them actually makes sense.


This article was originally published on Banking Daily.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: