Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

New RatHat Android malware uses AI to automate device control

Researchers reported on 17 September 2026 that the Android malware strain includes an AI subsystem to help operators navigate infected phones remotely.

By The Agentic Times ·

New RatHat Android malware uses AI to automate device control
· Image: bleepingcomputer.com

A new strain of Android malware called RatHat has been discovered, and it carries an AI-powered subsystem that helps its operators remotely navigate compromised devices, according to a report published by BleepingComputer on 17 September 2026.

The report describes RatHat as targeting Android users. The notable feature is not the remote access itself, but the automation layered on top of it: rather than an operator manually tapping through a stolen phone session, the malware includes a subsystem that uses AI to help move around the device. In effect, the attacker's workload shifts from driving every action to supervising an automated process.

That design matters for defenders because it changes the economics of mobile intrusion. Manual remote control of a phone is slow and does not scale well, since each infected device needs an operator's attention. Automated navigation, if it works as described, reduces the human time each victim requires. BleepingComputer's report does not quantify how effective the subsystem is in practice.

Several important details are not established in the available reporting. There is no named vendor or platform holder at fault, no confirmed initial infection route, and no figure for how many devices have been affected. The root cause of infections is unknown on the current evidence. Nor is there a confirmed date for when RatHat first appeared in the wild, only the date it was reported. We are not attributing the malware to any group, because the source does not.

The case fits a pattern that security teams have started to plan for, in which AI components are embedded into ordinary criminal tooling as a productivity feature rather than as a headline capability. A remote access trojan with an automation layer is still a remote access trojan: the defensive questions are how it gets installed, what permissions it requests, and what it can reach once it is running.

Until more technical detail is published, the practical advice for Android users is unchanged by this report and not specific to RatHat. Organisations running mobile fleets may want to ask their endpoint vendors whether detection coverage for this family exists, and to watch for follow-up analysis that fills in the distribution method and scale. We will update this story as further detail is confirmed by researchers or by Google.

Sources

  1. bleepingcomputer.comhttps://bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control