Rathat uses generative AI to adaptively navigate compromised devices, steal financial credentials and maintain persistent control even after a user attempts to uninstall the malicious application.
Distributed through smishing, malvertising and deceptive third-party download sites, Rathat disguises itself as a legitimate application and uses a multistage infection process to evade analysis. Once installed, it abuses Android Accessibility services to enable wireless debugging and autonomously pair with the device’s Android Debug Bridge (ADB). This allows the malware to break out of the standard application sandbox and execute commands with elevated privileges.
Unlike conventional malware that relies primarily on predefined scripts, Rathat uses generative AI to interpret the device interface and determine how to interact with on-screen elements in real time. This makes its activity more adaptable across devices and operating environments.
“Rathat represents a significant evolution in mobile malware, combining social engineering, advanced privilege escalation and AI-assisted device control within a single attack chain,” said Nico Chiaraviglio, Chief Scientist, Zimperium. “By establishing persistent access outside the application lifecycle, attackers can continue monitoring and controlling a compromised device even when the victim believes the threat has been removed.”
Rathat also employs multiple layers of anti-analysis and anti-debugging defences designed to disrupt automated security tools, decompilers and malware researchers. Its architecture demonstrates how attackers are moving beyond static mobile malware toward adaptive execution chains that can operate outside traditional application boundaries.






















