That Google Chrome download may be hiding something much nastier.
Security researchers have uncovered RatHat, a new Android malware strain that can disguise itself as legitimate apps, including by using a "Chrome" label, before abusing Android permissions to gain deep control over a victim's phone. The malware can capture passwords, PINs, and authentication codes, and can even reinstall itself after a user tries to remove it.
RatHat is not exploiting a vulnerability in Chrome. Instead, attackers use deceptive download sites and other social-engineering tactics to convince Android users to sideload malicious APK files.
RatHat can disguise itself as Chrome
Mobile security researchers at Zimperium discovered that RatHat was being distributed primarily through smishing and malicious advertisements that led victims to deceptive third-party download portals.
The malicious Android application can masquerade as legitimate software. Zimperium found one build configured to impersonate a well-known streaming app, while RatHat's dynamic configuration allows operators to change its launcher icon and label, including enabling an activity alias labeled "Chrome."
CNET reported that victims can encounter fake download pages that resemble the Google Play Store and are tricked into installing what appears to be Chrome. That distinction matters: RatHat does not exploit Chrome itself. Instead, familiar apps and branding can lure victims into installing malware outside Google's official app store.
Once installed, RatHat uses social engineering to obtain Android Accessibility permissions, but its infection chain goes further. Zimperium found that its dropper uses Android's native SessionInstaller APIs to bypass restricted settings and Accessibility Service protections during installation.
After Accessibility access is granted, RatHat can automatically navigate Android settings, unlock Developer Options, enable Wireless Debugging, and obtain the six-digit pairing code used by Android Debug Bridge, or ADB.
The malware then uses embedded ADB components to pair with the device's local ADB daemon, establishing shell-level access autonomously without requiring an external computer to complete the process.
Android malware has increasingly targeted legitimate system capabilities to gain greater control. ToxicPanda 2.0 similarly abuses Android features to attack financial apps.
AI helps RatHat navigate the phone
RatHat also incorporates generative AI into its device-control system.
According to Zimperium, the malware can serialize information from Android's live Accessibility tree into XML and communicate with a popular generative AI assistant that the researchers did not identify. The AI can help locate interface elements, interpret text displayed on the screen, and provide navigation instructions such as scrolling.
Zimperium says this approach makes RatHat's automation more adaptable than traditional scripted techniques that depend on predefined interface elements and actions.
Once RatHat establishes deeper access, it can deploy a Go-based agent with ADB shell privileges. A separate reverse-proxy client establishes a persistent tunnel to attacker-controlled infrastructure, giving operators continued access to the device.
RatHat can also display fake interfaces over banking and payment apps, intercept SMS messages and notifications, capture credentials and authentication codes, and monitor touch input to reconstruct PINs, passwords, and unlock patterns.
Those capabilities put RatHat in an increasingly crowded field of sophisticated Android threats. The recently discovered Manic malware can also steal credentials and PINs and relay them through other infected phones.
RatHat's persistence mechanism makes it particularly difficult to remove.
Zimperium found that the malware can intercept an uninstall attempt and display a fake failure message styled to look like Google Play. Even if a user successfully removes the malicious Android app, RatHat's local service operates outside the app's package lifecycle and can remain on the device.
That service can check whether the malicious app is still installed. If it is missing, RatHat can reinstall the APK and automatically restore runtime permissions and Accessibility access.
What Android users should do about RatHat
RatHat still needs users to open the door. The malware is distributed through tactics including malicious ads, text messages and deceptive download pages, giving users several opportunities to stop an infection before attackers gain deeper control.
Android users can reduce their risk by taking a few precautions:
- Stick to trusted app stores. Avoid installing APK files delivered through text messages, online ads, or unfamiliar websites. A page that looks like Google Play may not actually be Google's official store.
- Be suspicious of unexpected Chrome downloads. If Chrome is already installed, don't trust any website or message that claims you need to download or reinstall it from another source.
- Check Accessibility permissions. RatHat relies on Accessibility access as part of its path toward deeper device control. Apps without a legitimate reason to control the screen should not have this permission.
- Watch Developer Options and Wireless Debugging. Unexpected changes to these settings could be a warning sign, particularly on devices where they are normally disabled.
- Keep Android updated and Play Protect enabled. Google recommends keeping Android and Google Play system updates current, enabling Play Protect, and removing apps that users don't recognize, trust, or remember installing.
Users who think RatHat has already compromised their phone should treat the situation more seriously than a normal unwanted app. Simply deleting the suspicious application may not be enough because RatHat's separate local service can survive removal of the primary app and reinstall it.
If signs of malware continue, Google says users may need to reset their Android device or contact their device manufacturer for help. A factory reset erases the device's data, so users should review Google's reset and backup instructions before taking that step.
Users should also change passwords for banking, email, and other sensitive accounts from a separate trusted device and review those accounts for unauthorized activity.
The simplest defense comes much earlier in the attack: don't trust an unexpected Chrome download simply because the page offering it looks like Google Play.
Related reading: For another Android threat, read how Mantax Otax combines spyware and ransomware to steal data and take control of infected phones.





