Observed Signal · Sep 22, 2026 · Technical Release · Source: t3n · Impact: 2/5 · Sentiment: Negative
AI-powered Android malware Rathat discovered requiring factory reset
Security researchers at Zimperium uncovered a new Android malware named 'Rathat' that disguises itself as legitimate apps, including a fake Google Chrome. It tricks users into granting accessibility permissions, then enables Wireless Debugging to gain ADB shell access, installing an AI agent that coordinates malicious actions such as stealing banking credentials, intercepting SMS, and capturing screen activity. The malware operates stealthily, evades uninstallation, and can wipe the device if detected. Over 162 infected apps have been found, primarily targeting Chinese payment apps like WeChat Pay and Alipay, but it poses a global threat. Google states that Play Store protections can detect Rathat, advising users to install only from official sources. Infected devices require a factory reset to remove the malware.
Relevant to mobile security, affecting Android users and potentially impacting ad ecosystem via device compromise, but not directly AdTech-related.
Track Google Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Zimperium discovered Android malware 'Rathat' disguised as a fake Chrome browser.
- The malware uses accessibility permissions to enable Wireless Debugging and gain ADB shell access.
- Rathat installs an AI agent to coordinate data exfiltration and system persistence.
- Over 162 infected apps were found, primarily targeting Chinese payment apps like WeChat Pay and Alipay.
- Google Play Store can detect and remove Rathat apps; users should install only from official sources. Infected devices require a factory reset.
Connected Companies & Entities
1 Entity mapped“Ein Google-Sprecher betonte, der Play Store erkennt Rathat....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
New Android Trojans Target Over 800 Apps
Security researchers at Zimperium have identified four new Android trojans — RecruitRat, SaferRat, Astrinox and Massiv — that target banking and social-media applications. The trojans together aim at credentials and transaction theft across more than 800 apps. The malware can actively hide on infected devices (for example by replacing app icons with transparent images), remain dormant to evade initial scans, download additional payloads later, and hide malicious code inside ZIP structures. Researchers observed distribution vectors including fake job portals and illegal streaming sites; one trojan mimics the HR service Hirex. Users are advised to avoid sideloading apps from unknown websites and to use official app stores such as Google Play or trusted alternatives like F‑Droid.
AI-Agent 'Jadepuffer' Runs Adaptive Ransomware
Security researchers at Sysdig uncovered a novel ransomware attacker dubbed “Jadepuffer” that appears to be controlled by an AI agent. The agent used natural-language-driven code and rapid iterative problem-solving — in one case completing an adaptation in 31 seconds — to place ransomware. It exploited a vulnerability in the open-source Langflow framework to harvest unencrypted cloud credentials and API keys, which enabled lateral movement and persistent tasks. Jadepuffer targeted MySQL servers running the Alibaba Nacos configuration service, creating admin accounts and encrypting 1,342 configuration files before deleting originals. The attacker generated a ransom table with a Bitcoin wallet and Proton‑Mail contact; analysts report the wallet moved roughly 46 BTC across about 73 transactions. Researchers warn AI agents lower the skill barrier for automated, adaptive cyberattacks against unpatched systems.
Google adds AI scam-call warning to Android Phone app
Google has introduced a new AI-based scam-call warning in its Android Phone app to help users detect calls that use AI-generated voices to impersonate contacts. The feature, available free via Google Play and automatically active for users of the Google Phone app, exchanges encrypted real-time data between devices to verify whether the displayed caller is the genuine contact; if verification fails the app pings the alleged contact's device and, based on the response, warns the recipient, reports and blocks the number. The rollout begins this month on Pixel phones and will expand to other Android devices running Android 12 or later. Google built the system on the RCS standard so other companies can implement the same verification in other calling apps.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
