LIVE FEED
RatHat Android Trojan Uses AI for Real-Time Evasion

RatHat Android Trojan Uses AI for Real-Time Evasion

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 SecurityWeek

The RatHat Android trojan leverages AI to enable real-time device navigation and control, representing a shift in mobile malware sophistication. By integrating AI-driven automation, the malware can adapt its behaviour dynamically, making detection and remediation significantly harder for traditional security tools. This development signals a broader trend of threat actors embedding AI capabilities directly into offensive tooling.

RatHat Android Malware Uses Generative AI to Control Devices

RatHat Android Malware Uses Generative AI to Control Devices

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 6.2 The Hacker News

RatHat is a sophisticated Android RAT attributed to China-based threat actors that abuses Android Debug Bridge (ADB) to maintain persistent shell access even after the malware is uninstalled. Notably, the malware integrates a generative AI assistant to parse on-screen accessibility trees and autonomously direct device interactions, representing an emerging class of AI-augmented mobile threats. Its layered anti-analysis techniques and persistence mechanisms make it a significant threat to Android users targeted via smishing and malvertising campaigns.

AI-Generated Zero-Day: 2FA Bypass in Web Admin Tool

AI-Generated Zero-Day: 2FA Bypass in Web Admin Tool

ATLAS OWASP CRITICAL Active exploitation · Immediate action required ▲ 9.2 The Hacker News

Google's Threat Intelligence Group has confirmed the first known instance of a threat actor using an AI model to discover and weaponize a zero-day vulnerability — a 2FA bypass in a popular open-source web administration tool. The exploit, delivered via a Python script bearing hallmarks of LLM-generated code (including hallucinated CVSS scores and structured docstrings), was designed for mass exploitation. This marks a significant inflection point in the offensive AI threat landscape, demonstrating that AI-assisted vulnerability discovery and weaponization has moved from theoretical risk to confirmed operational reality.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.