Google says its current detection found no apps containing RatHat on Google Play, and that Play Protect protects against known versions on Android devices with Google Play Services. Zimperium describes RatHat as Android malware that can use Accessibility access and Wireless Debugging to reach deeper device control and target credentials.

What Zimperium reports about RatHat

In an analysis dated September 16, 2026, Zimperium described RatHat as malware delivered through targeted text-message phishing, malicious ads and deceptive third-party download portals. The lures lead users to install an Android application package, or APK, outside the usual app-store process.

Zimperium says RatHat seeks Accessibility access, then uses simulated interactions to enable Developer Options and Wireless Debugging. It reads the displayed Android Debug Bridge (ADB) pairing code and port, then pairs with the device’s local ADB service. That access lets the malware stage a Go-based agent and a reverse-proxy client outside the visible app’s ordinary lifecycle.

AI-assisted navigation and data collection

Zimperium says RatHat sends the phone’s live Accessibility tree—the structured information apps expose about interface elements—to a generative-AI assistant. The assistant helps identify screen targets, read text and guide actions such as scrolling.

Earlier NeoTeo coverage discussed RatHat’s reported AI-assisted device prioritization; Zimperium’s analysis describes a different use: navigating the phone’s interface.

Zimperium also reports credential-stealing overlays aimed at banking and payment apps, along with interception of SMS messages and notifications that may contain one-time codes. Other reported collection methods include screen capture, browser-address harvesting, text-event keylogging and raw touch-coordinate monitoring. By comparing touch points with keypad layouts or a 3 × 3 pattern-lock grid, the malware can attempt to infer PINs, passwords or unlock patterns.

Persistence after the visible app is removed

A separate local service may remain after the visible RatHat app is uninstalled, according to Zimperium. The service can reinstall the app and restore permissions; the analysis also describes fake uninstall-error overlays and possible abuse of Android’s Device Admin feature.

What Google says about Play Protect

Google says its current detection found no apps containing RatHat on Google Play. It also says Play Protect protects against known versions on Android devices with Google Play Services. Zimperium’s account describes distribution through deceptive third-party portals and sideloaded APKs.