New RatHat Android malware uses AI to automate device control

Executive Summary

A new Android RAT named RatHat has been identified. It incorporates an AI‑powered subsystem that assists operators in remotely navigating and controlling compromised devices, automating tasks such as data exfiltration and lateral movement. The malware can adapt its actions based on device state, making it a sophisticated threat for mobile platforms.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-17T21:50:26+00:00 - Category: threat-intel

Original Description: A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]

"Yesterday is history. Tomorrow is a mystery. And today? Today is a gift that's why they call it the present."

— Unknown
Source: Bleeping Computer