Zimperium - Experts & Thought Leaders
Latest Zimperium news & announcements
Zimperium, the pioneer in AI-empowered mobile security, today released new analysis warning that agentic AI is making sophisticated mobile app attacks easier to develop, adapt and scale. Agentic AI systems can independently plan and execute tasks, learn from unsuccessful attempts and adjust their approach until an objective is achieved. Applied to mobile attacks, these capabilities allow threat actors to automate work that previously required extensive time and specialized expertise, including analyzing app defences, identifying ways to bypass security controls and replicating successful attacks across multiple devices. Malware targeting credentials “Agentic AI is transforming complex mobile attacks into repeatable operations that can be initiated with simple, natural-language instructions,” said Pat Shueh, VP of Product Management, MAPS, at Zimperium. “The concern is not that AI has created an entirely new vulnerability class. It has removed many of the technical barriers that once limited who could execute these attacks and how quickly they could scale.” The warning follows Zimperium’s recent analysis of RatHat, an AI-powered mobile malware targeting credentials and financial accounts. RatHat provides evidence that AI is already becoming part of the mobile threat landscape, while emerging agentic AI frameworks could give attackers even greater autonomy and speed. Agentic AI frameworks Once an agent identifies a successful attack path, it can translate that process into a reusable script and deploy it across fleets of devices or emulators. It can also reassess and regenerate the attack when an application changes, reducing the cost and effort required to maintain mobile fraud operations. This shift increases the need for mobile app security that can withstand both static and dynamic analysis, tampering and manipulation at runtime. Organizations must protect applications throughout their lifecycle, from development and app store distribution through execution on end-user devices.
Zimperium, the pioneer in AI-empowered mobile security, announces that its zLabs research team has uncovered RatHat, an advanced Android malware strain linked to threat actors believed to be operating in China. RatHat uses generative AI to adaptively navigate compromised devices, steal financial credentials and maintain persistent control even after a user attempts to uninstall the malicious application. Distributed through smishing, malvertising and deceptive third-party download sites, RatHat disguises itself as a legitimate application and uses a multistage infection process to evade analysis. Once installed, it abuses Android Accessibility services to enable wireless debugging and autonomously pair with the device’s Android Debug Bridge (ADB). This allows the malware to break out of the standard application sandbox and execute commands with elevated privileges. Advanced privilege escalation Unlike conventional malware that relies primarily on predefined scripts, RatHat uses generative AI to interpret the device interface and determine how to interact with on-screen elements in real time. This makes its activity more adaptable across devices and operating environments. “RatHat represents a significant evolution in mobile malware, combining social engineering, advanced privilege escalation and AI-assisted device control within a single attack chain,” said Nico Chiaraviglio, Chief Scientist, Zimperium. “By establishing persistent access outside the application lifecycle, attackers can continue monitoring and controlling a compromised device even when the victim believes the threat has been removed.” Accessibility-based capture Zimperium researchers identified several advanced RatHat capabilities: Hardware-level credential theft: RatHat monitors raw touchscreen input to reconstruct PINs, passwords and device-unlock patterns, bypassing protections that prevent screenshots or Accessibility-based capture. Banking and payment fraud: Fraudulent overlays imitate legitimate banking, cryptocurrency and payment applications to capture login credentials and intercept one-time passcodes. AI-assisted device control: Generative AI helps the malware interpret on-screen content, locate interface elements and navigate the device dynamically. Self-restoring persistence: A hidden service operates independently of the original application, allowing RatHat to reinstall itself and restore malicious permissions after the application is removed. Persistent remote access: A concealed reverse-proxy tunnel provides attackers with an ongoing path into the device while helping communications bypass traditional network controls. Traditional application boundaries RatHat also employs multiple layers of anti-analysis and anti-debugging defenses designed to disrupt automated security tools, decompilers and malware researchers. Its architecture demonstrates how attackers are moving beyond static mobile malware toward adaptive execution chains that can operate outside traditional application boundaries. Zimperium Mobile Threat Defense (MTD) provides on-device detection against RatHat’s malicious payloads, phishing infrastructure, Accessibility abuse, privilege escalation and command-and-control activity. Zimperium Mobile Runtime Protection (zDefend) helps financial institutions, payment providers and other application owners detect overlays, screen capture, debugging services and compromised environments before credentials can be stolen.
Zimperium, the global pioneer in AI-empowered mobile security, announces that its zLabs research team has uncovered Mantax Otax, a sophisticated Android malware campaign that combines ransomware, spyware, credential theft, and remote device control in a single infection. The malware appears to target victims in Indonesia and is distributed as a standalone Android application through third-party file-sharing services, using phishing and social engineering to persuade users to sideload it. Once installed, Mantax Otax seeks device administrator and Accessibility permissions, giving attackers broad control over the compromised device. Disruptive visual overlays The malware can steal lock-screen PINs, intercept SMS messages and one-time passwords, collect contacts and call logs, access browser history, exfiltrate files and photos, capture images through the device’s cameras, and harvest WhatsApp and Telegram communications. It can also take screenshots, record and stream the screen, block applications, disable touch input, and remotely play audio or disruptive visual overlays. On devices running Android 9 and earlier, Mantax Otax can encrypt a broad range of files using a unique key retrieved from its command-and-control infrastructure, delete the originals, and replace local images with ransom notices. It then displays an on-device chat interface through which the attacker can communicate directly with the victim and demand payment. Android 10 and later limit the ransomware component’s access to files through Scoped Storage, but the malware’s surveillance, credential theft, and device-control capabilities remain a significant threat. Disrupting attacker communications “Mantax Otax shows how mobile ransomware is evolving beyond file encryption into a broader device-compromise and extortion model,” said Vishnu Pratapagiri, mobile security researcher at Zimperium zLabs. “By combining surveillance, credential theft, communications harvesting, and remote control, attackers gain multiple ways to pressure victims and exploit the sensitive data flowing through their mobile devices. This campaign reinforces why organizations need continuous, on-device protection that can detect malicious behavior before an attacker gains control.” Zimperium Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) detect the analyzed Mantax Otax samples through on-device, dynamic detection. Zimperium MTD Web Content Filtering can also block known malicious distribution sites and command-and-control traffic, helping prevent installation and disrupt attacker communications if a device is compromised. The full technical analysis, including indicators of compromise and mapped MITRE ATT&CK techniques, is available on the Zimperium blog.