RatHat is an Android malware threat that uses an AI chatbot alongside a device’s debugging tools. According to research from Zimperium, it can target login details, record PIN-related input, and remain active even after the original fake app is uninstalled.
Google stated that no apps containing RatHat were found on the Google Play Store based on its current detection. Android devices with Google Play Services are automatically protected against known versions of the malware through Google Play Protect, which is enabled by default.
How RatHat Reaches Android Devices
RatHat primarily spreads through smishing messages and malvertising. These tactics direct people to fraudulent download pages that can initially appear legitimate but are outside the Google Play Store.
The malware is installed when a person sideloads the fake app onto their Android device. After installation, RatHat abuses Android accessibility settings to activate Developer Options and Wireless Debugging. It then pairs with the phone’s debugging bridge, giving it shell-level control.
How RatHat Uses an AI Chatbot
RatHat sends a live representation of activity on the device screen to what the research describes as one of the world’s most popular generative AI assistants.
The malware asks the chatbot to identify screen content, including on-screen text and the purpose of buttons. In effect, the AI component helps RatHat interpret what is happening on the device and determine its next action.
This approach gives the malware a way to react to what appears on a target’s screen while it operates through the infected device.
What RatHat Can Target
RatHat’s activity begins through the fake app installed on the device. It can use fraudulent login overlays on banking and cryptocurrency apps, record the screen, and intercept one-time codes.
These functions can give the malware access to sensitive information entered or displayed on the device.
RatHat also runs a separate persistent background process that includes a hardware-level keylogger. It reads raw touch-input coordinates from the kernel’s touchscreen driver and compares finger movements with stored keypad layouts. This allows it to determine lock-screen PINs and patterns.
Why Uninstalling the Fake App May Not Remove RatHat
Removing the fake app may not fully remove RatHat from a device. The malware can display a false Google Play Store error that makes it appear that the uninstall did not work.
Even if the app is successfully deleted, a hidden background process can restore it while retaining its permissions. That persistence is what makes RatHat difficult to remove through a standard uninstall alone.
Steps Mentioned for Avoiding RatHat
Zimperium recommends avoiding sideloaded apps, treating accessibility permission requests with caution, and keeping Google Play Protect scanning turned on.
For a device that is already affected, the reported options are manual cleanup through Android Debug Bridge or a factory reset.

