September 22, 2026
Android Trojan is harder to remove: RatHat uses AI and restores its APK
On September 16, 2026, Zimperium zLabs described RatHat, which uses AI to read the Android interface and steal payment-service credentials. Once granted Accessibility Service, the trojan taps Build Number seven times, enables Wireless Debugging, and reads a six-digit code to access the device. It replaces the uninstall screen with a fake Google Play error, while a separate service restores the APK.

Previously, Android trojans followed predefined scripts. RatHat now exports the screen structure to XML, and GenAI returns where to tap, what to read, or when to scroll. This lets the trojan spoof screens from WeChat, Alipay, and other banking and crypto apps.
How it infects. RatHat is distributed through lure SMS messages, ads with malicious links, and third-party forums. Victims are persuaded to download the APK manually. Researchers link the trojan to actors believed to operate from China.
Android protection. On September 17, Google said RatHat was not found on Google Play, and that default-enabled Play Protect covers known variants on devices with Google Play Services. The scan setting is in Play Store: profile → Play Protect → Settings → Scan apps with Play Protect.
For a confirmed infected device, Malwarebytes recommends a factory reset: Google advises recalling your account login and password beforehand, charging the device to 70%, and notes that a reset of up to an hour will erase all data.
Source
