AI-Driven RatHat Malware Hijacks Android Devices for Credential Theft
September 17, 2026
oecd:2026-09-17-8e21View source ↗
What happened
Security researchers have identified RatHat, a new Android malware strain linked to China-based actors, that uses generative AI to automate device control, steal banking credentials, and evade detection. Distributed via phishing, malvertising, and third-party app stores, RatHat abuses accessibility permissions to gain deep access and persist on infected devices.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
AI-Driven RatHat Malware Hijacks Android Devices for Credential Theft
2026-09-17