Tendvane

← All articles

SecuritySeptember 18, 2026

This Android trojan asks an AI chatbot where to tap next

The permission to be careful about on an Android phone is not the camera or the microphone. It is Accessibility.

Zimperium's zLabs team published research this week on RatHat, a banking trojan whose operators appear to be Chinese-speaking, and everything clever it does begins with that one tap of approval. Once granted Accessibility, RatHat quietly switches on Developer Options and Wireless Debugging, then pairs itself with the phone's own debugging interface. From there it runs with privileges an ordinary app never receives. It drops fake login screens over banking, payment and cryptocurrency apps, WeChat and Alipay among them. It reads incoming texts and notifications, including one-time codes. It scrapes addresses out of the browser bar and captures the PIN or pattern used to unlock the screen.

The automation is what got it noticed. Instead of following a fixed script, RatHat takes whatever is currently on screen, converts the layout into XML and sends it to a mainstream generative AI assistant, asking in Mandarin where to tap and what to do next. Back come coordinates and instructions such as SCROLL_DOWN. A scripted trojan falls over the moment an app redesigns its buttons. This one simply looks again.

None of it comes from Google Play. It arrives by text message, through malicious adverts, and from third-party sites offering an APK of something you were looking for. Leaving installation from unknown sources switched off, and treating any app that requests Accessibility as suspect unless it genuinely is a screen reader, shuts the door. The accounts at risk are mostly the same ones you use on the PC, and Tendvane's privacy and accounts check will show you which of those are signed in on your machine and how well they are protected.

Sources

Download Tendvane