New Android malware can deploy AI to automate device control and it can even bring itself back from the dead
Date:
Fri, 18 Sep 2026 19:15:00 +0000
Description:
AI can now serve as the eyes and the hands of a piece of malware and even reinstall components if they're removed.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Zimperium zLabs discovered RedHat , a Chineseorigin Android banking trojan with AI assistant AI interprets screen layouts in realtime, enabling credential theft and
bypassing app redesigns Distributed via thirdparty stores, social media, malvertising, and SMS; persistence blocks uninstall attempts There is an Android malware out there that comes with an AI assistant that tells it what to do. The assistant seems to be independent of the malwares operator, allowing the tool to work without requiring the operators to be present in real-time.
The malware in question is called RedHat. It was discovered by security researchers Zimperium zLabs, who believe it is of Chinese origin. It is currently being distributed via third-party app stores, social media, malvertising, and SMS spam, and requires Androids Accessibility permissions
to work. The malware itself is a typical banking trojan - it creates an invisible overlay every time the victim brings up a banking app, capturing login credentials and one-time passwords, and thus giving attackers direct control over peoples banking accounts. Latest Videos From TechRadar Watch
full video here: AI-powered eyes But what makes RedHat stand out from a sea
of Android banking trojans is its AI-powered component. The model serves as a kind of remote eyes and hands for controlling the victims phone.
Usually, when criminals develop banking trojans, they need to code exact coordinates of the layout for it to work. They need to code where the
password is entered, or where the login button is. If the banking app gets redesigned and changes its layout, the malware breaks. You may like This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target Experts warn hackers are using AI chatbots to write malware using natural language A new Android attack combines malware and ransomware in a cocktail of cybercrime
With AI, that is no longer a problem. RedHat gets a picture of whats on the screen, sends it to the AI assistant, which then instructs the malware on how to proceed.
"RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," Zimperium explained. Are you a pro? Subscribe to our newsletter Sign up to the
TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
The tool also has a few advanced persistence mechanisms, being capable of reinstalling deleted components, and intercepting the uninstall process to cancel it while displaying a fake error message to the victim.
So far, there is no word on who the targets are, or how many people might
have been compromised.
Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/new-android-malware-can-deploy-ai-to-au tomate-device-control-and-it-can-even-bring-itself-back-from-the-dead
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)