New Android malware 'RedHat' uses AI to automate device control and evade detection

Security researchers at Zimperium zLabs have identified a sophisticated new Android banking trojan dubbed 'RedHat'. Unlike traditional malware that relies on hard-coded scripts, RedHat utilizes an AI assistant to interpret screen layouts in real-time. This allows the malware to navigate banking applications dynamically, effectively bypassing interface redesigns that would typically break older automation tools. Distributed through third-party app stores, social media, and SMS campaigns, the malware requests Accessibility permissions to capture login credentials and one-time passwords. Furthermore, RedHat features advanced persistence mechanisms, including the ability to intercept uninstall attempts and reinstall deleted components. By automating device interaction through AI, the trojan becomes significantly more adaptable and difficult for security software to detect. While the specific targets and scale of the campaign remain unclear, the discovery highlights a concerning evolution in how malicious actors leverage artificial intelligence to enhance the efficacy of mobile cyberattacks.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


