For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/rathat-ai-navigates-infected-android-phones.md.
AI Security ↗

RatHat: how AI helps malware navigate an Android phone

Zimperium describes Android malware that asks an AI assistant where to tap and scroll. The model helps navigate a phone the malware has already compromised.

AI-generated illustration: a phone shows a conceptual navigation menu with a highlighted control and scroll arrow.
AI-generated illustration. The interface is a concept, not a screenshot of RatHat.

In brief: RatHat uses a generative AI assistant to help navigate an infected Android phone, according to Zimperium. The malware provides access to the device; the model helps interpret what is on its screen.

Mobile security company Zimperium highlighted RatHat in a 22 September warning about AI-assisted mobile attacks. Its broader assessment is that AI can reduce the effort needed to adapt attacks when applications change. RatHat offers a specific example of the role a model can play.

How software can read and operate a screen

Android has accessibility services for people who need help interacting with their devices. Screen readers and voice-control tools are familiar examples.

Android’s documentation explains that these services can inspect a structured description of the interface, including buttons, lists and text. With the appropriate configuration, they can also click and scroll on the user’s behalf. These are legitimate capabilities intended to make the device usable.

A description of a screen is different from a screenshot: it can identify individual controls and the text attached to them. That gives software information it can use to find a particular button.

Where RatHat uses the model

In its 16 September technical report, Zimperium says RatHat sends this screen structure to a generative AI assistant. Responses help locate controls, read text and choose navigation actions. The report does not name the assistant.

The same research describes deceptive downloads and abuse of accessibility access, alongside credential theft. The model is one component of an infection chain, not the source of the phone’s permissions.

What the finding establishes

This is a useful distinction within AI hacking. Writing malware, navigating an infected device and independently planning an entire intrusion are different capabilities.

For a business, the relevant issue is what software can do once it has access to a phone used for work. An ordinary navigation request can become a step in a harmful operation when malicious software decides why it is being performed. Zimperium’s report illustrates that combination; it does not establish that a chatbot can take over an untouched phone.

← Back to all insights
Questions or inquiry? [email protected] Contact us →