There is a terrifying new digital threat that Android users need to be aware of. New AI-powered malware called RatHat can automatically gain administrator-level control over your Android device, stealing whatever it wants. RatHat was discovered by mobile security company Zimperium, which notes that the program tricks people into downloading what appears to be a legitimate application, such as Google Chrome, through a fake web page that imitates the Google Play Store. Once opened, the app seemingly innocently asks for accessibility permissions, which it then uses to control the entire device. RatHat uses the accessibility permissions that users grant it to navigate your phone’s menu system and unlock wireless debugging, a legitimate development tool commonly used in application testing, and then grants itself ADB Shell permissions. This effectively gives the malware administrator access to your device. RatHat then installs an AI-assisted agent that executes system commands to steal information and a proxy client that channels that stolen information to the hacker. “That type of infection chain is not necessarily more complex than, say, following a phishing email on Windows and saying yes when the program asks for administrator permissions,” Sav Wheeler, a research engineer at Malwarebytes, said in an email. “Climbing the Android landscape often depends on giving apps additional permissions that the operating system blocks by default to keep devices secure.” According to Zimperium, the malware can be traced back to attackers in China and primarily targets apps like WeChat Pay and Alipay, which are as popular in China as Apple Pay and Venmo in the United States. Malwarebytes notes that other financial applications can also be attacked. So far, researchers have found 162 infected apps in the wild, reporting to a dozen attacker-run servers. What can this malware do? The worrying part is that the malware doesn’t do anything strange that the user can immediately notice, unlike a ransomware attack. Instead, it waits for the right moment, runs in the background, and captures information that appears on the screen, including usernames, passwords, and two-factor authentication codes. It can also steal raw touch inputs from your touch screen, allowing you to recreate PIN codes and pattern unlock codes. It can also capture SMS messages, thus intercepting security codes. There’s not much the app can’t steal if it wants to. How do I know if I have RatHat on my phone? Most people will probably never encounter RatHat. You have to download a malicious app to do this, so sticking to the Play Store avoids this whole problem. A Google spokesperson confirmed to CNET in an email that Google Play Protect, which is enabled by default on Android devices with Google Play Services, already recognizes and protects against RatHat and that “no apps containing this malware are found on Google Play.” The only other way to find it is to run an antivirus scan that detects the software. Malwarebytes on Google Play is a solid option. Get started with a 14-day free trial of the pro version, which includes real-time protection. But even if you stick with the more limited free version after the 14-day trial, you can still run scans to detect malware. RatHat is publicly documented malware, so most other reputable Android antivirus apps should be able to find it as well. The bad news is that RatHat is sneaky and difficult to quarantine. “Unfortunately, due to the behavior of the program itself (redisguised as other applications, dynamically changing its behavior using the AI endpoint), static analysis and quarantining are not enough to remove malware,” Wheeler said. In short, the only way to get rid of this malware is to perform a hard factory reset of your device. This effectively removes hidden secondary files that malware installs, which antivirus applications cannot handle. Uninstalling the app doesn’t work because the malware retains your administrator access through those hidden files, which then allow you to reinstall the app over and over again. How do I avoid RatHat? This is also good news. RatHat’s infection method is complex and can be thwarted at multiple points during the process. Firstly, you should never click on a link in an SMS or email from a source you don’t know or trust. That stops almost all social engineering threats in the first place, including RatHat. Verify that you are using the official Google Play app instead of a deceptive imitation website. Look at the top of the screen. If it has an address bar where you type URLs, it’s just a website disguised as an app. Real apps don’t have address bars. Also, keep in mind that pre-installed or existing versions of Chrome do not require reinstallation, so if you are asked to reinstall an app you know you have, think twice. Denying accessibility permissions is the critical last line of defense against mobile malware. While downloading a malicious application is risky, the software remains largely powerless until it is granted advanced system privileges. Wheeler says SMS phishing is targeted to each specific user, so you won’t see the same phishing attempt as someone else, and the tactics the app uses vary from region to region. Following standard anti-phishing practices and not enabling accessibility permissions largely eliminates the RatHat threat. Joe is a freelance journalist. It all started with a long-standing hobby of building his own PCs, something he first did as a teenager. It became a permanent pleasure to put words on the Internet about the subject. He has written for CNET, PCMag, Mashable, and SlashGear as a freelance writer and worked as a senior editor at Android Authority for 10 years. When he’s not writing about technology and science, he’s learning the ins and outs of DIY home repairs, gaming, playing his basses, and posting PC building help and gaming subreddits. He is a firm believer that orange juice should have pulp. See full biography